diff --git a/.gitignore b/.gitignore index 3814395..141b2e8 100644 --- a/.gitignore +++ b/.gitignore @@ -13,7 +13,3 @@ /iptables-1.8.7.tar.bz2 /iptables-1.8.8.tar.bz2 /iptables-1.8.9.tar.xz -/iptables-1.8.10.tar.xz -/iptables-1.8.10.tar.xz.sig -/iptables-1.8.11.tar.xz -/iptables-1.8.11.tar.xz.sig diff --git a/0001-extensions-NAT-Fix-for-Werror-format-security.patch b/0001-extensions-NAT-Fix-for-Werror-format-security.patch new file mode 100644 index 0000000..cecd191 --- /dev/null +++ b/0001-extensions-NAT-Fix-for-Werror-format-security.patch @@ -0,0 +1,30 @@ +From ff8eacec604537d98eb912281fa0c5c6a83da717 Mon Sep 17 00:00:00 2001 +From: Phil Sutter +Date: Thu, 12 Jan 2023 14:38:44 +0100 +Subject: [PATCH] extensions: NAT: Fix for -Werror=format-security + +Have to pass either a string literal or format string to xt_xlate_add(). + +Fixes: f30c5edce0413 ("extensions: Merge SNAT, DNAT, REDIRECT and MASQUERADE") +Signed-off-by: Phil Sutter +(cherry picked from commit ed4082a7405a5838c205a34c1559e289949200cc) +--- + extensions/libxt_NAT.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/extensions/libxt_NAT.c b/extensions/libxt_NAT.c +index da9f22012c5d6..2a6343986d54f 100644 +--- a/extensions/libxt_NAT.c ++++ b/extensions/libxt_NAT.c +@@ -424,7 +424,7 @@ __NAT_xlate(struct xt_xlate *xl, const struct nf_nat_range2 *r, + if (r->flags & NF_NAT_RANGE_PROTO_OFFSET) + return 0; + +- xt_xlate_add(xl, tgt); ++ xt_xlate_add(xl, "%s", tgt); + if (strlen(range_str)) + xt_xlate_add(xl, " to %s", range_str); + if (r->flags & NF_NAT_RANGE_PROTO_RANDOM) { +-- +2.40.0 + diff --git a/0002-etc-Drop-xtables.conf.patch b/0002-etc-Drop-xtables.conf.patch new file mode 100644 index 0000000..e676561 --- /dev/null +++ b/0002-etc-Drop-xtables.conf.patch @@ -0,0 +1,132 @@ +From 55f3f1743934efa33df1ecbe11b31362fc45b03c Mon Sep 17 00:00:00 2001 +From: Phil Sutter +Date: Tue, 17 Jan 2023 16:38:43 +0100 +Subject: [PATCH] etc: Drop xtables.conf + +The file is not used since the commit this one fixes. Also it wasn't +installed until recently, when commit 3822a992bc277 ("Makefile: Fix for +'make distcheck'") added it in the wrong spot in an attempt to reduce +differences between tarballs generated by 'make tarball' and 'make +dist'. + +While being at it, drop stale xtables_config_main() prototype from +xtables-multi.h. + +Fixes: 06fd5e46d46f7 ("xtables: Drop support for /etc/xtables.conf") +Signed-off-by: Phil Sutter +(cherry picked from commit ca8fb6c21b298b3d96db2bfbf9c74d393bdd4728) +--- + Makefile.am | 2 +- + etc/xtables.conf | 74 ---------------------------------------- + iptables/xtables-multi.h | 1 - + 3 files changed, 1 insertion(+), 76 deletions(-) + delete mode 100644 etc/xtables.conf + +diff --git a/Makefile.am b/Makefile.am +index 451c3cb2d5887..299ab46d7b8e2 100644 +--- a/Makefile.am ++++ b/Makefile.am +@@ -20,7 +20,7 @@ EXTRA_DIST = autogen.sh iptables-test.py xlate-test.py + + if ENABLE_NFTABLES + confdir = $(sysconfdir) +-dist_conf_DATA = etc/ethertypes etc/xtables.conf ++dist_conf_DATA = etc/ethertypes + endif + + .PHONY: tarball +diff --git a/etc/xtables.conf b/etc/xtables.conf +deleted file mode 100644 +index 3c54ced043d82..0000000000000 +--- a/etc/xtables.conf ++++ /dev/null +@@ -1,74 +0,0 @@ +-family ipv4 { +- table raw { +- chain PREROUTING hook NF_INET_PRE_ROUTING prio -300 +- chain OUTPUT hook NF_INET_LOCAL_OUT prio -300 +- } +- +- table mangle { +- chain PREROUTING hook NF_INET_PRE_ROUTING prio -150 +- chain INPUT hook NF_INET_LOCAL_IN prio -150 +- chain FORWARD hook NF_INET_FORWARD prio -150 +- chain OUTPUT hook NF_INET_LOCAL_OUT prio -150 +- chain POSTROUTING hook NF_INET_POST_ROUTING prio -150 +- } +- +- table filter { +- chain INPUT hook NF_INET_LOCAL_IN prio 0 +- chain FORWARD hook NF_INET_FORWARD prio 0 +- chain OUTPUT hook NF_INET_LOCAL_OUT prio 0 +- } +- +- table nat { +- chain PREROUTING hook NF_INET_PRE_ROUTING prio -100 +- chain INPUT hook NF_INET_LOCAL_IN prio 100 +- chain OUTPUT hook NF_INET_LOCAL_OUT prio -100 +- chain POSTROUTING hook NF_INET_POST_ROUTING prio 100 +- } +- +- table security { +- chain INPUT hook NF_INET_LOCAL_IN prio 50 +- chain FORWARD hook NF_INET_FORWARD prio 50 +- chain OUTPUT hook NF_INET_LOCAL_OUT prio 50 +- } +-} +- +-family ipv6 { +- table raw { +- chain PREROUTING hook NF_INET_PRE_ROUTING prio -300 +- chain OUTPUT hook NF_INET_LOCAL_OUT prio -300 +- } +- +- table mangle { +- chain PREROUTING hook NF_INET_PRE_ROUTING prio -150 +- chain INPUT hook NF_INET_LOCAL_IN prio -150 +- chain FORWARD hook NF_INET_FORWARD prio -150 +- chain OUTPUT hook NF_INET_LOCAL_OUT prio -150 +- chain POSTROUTING hook NF_INET_POST_ROUTING prio -150 +- } +- +- table filter { +- chain INPUT hook NF_INET_LOCAL_IN prio 0 +- chain FORWARD hook NF_INET_FORWARD prio 0 +- chain OUTPUT hook NF_INET_LOCAL_OUT prio 0 +- } +- +- table nat { +- chain PREROUTING hook NF_INET_PRE_ROUTING prio -100 +- chain INPUT hook NF_INET_LOCAL_IN prio 100 +- chain OUTPUT hook NF_INET_LOCAL_OUT prio -100 +- chain POSTROUTING hook NF_INET_POST_ROUTING prio 100 +- } +- +- table security { +- chain INPUT hook NF_INET_LOCAL_IN prio 50 +- chain FORWARD hook NF_INET_FORWARD prio 50 +- chain OUTPUT hook NF_INET_LOCAL_OUT prio 50 +- } +-} +- +-family arp { +- table filter { +- chain INPUT hook NF_ARP_IN prio 0 +- chain OUTPUT hook NF_ARP_OUT prio 0 +- } +-} +diff --git a/iptables/xtables-multi.h b/iptables/xtables-multi.h +index 94c24d5a22c7e..833c11a2ac914 100644 +--- a/iptables/xtables-multi.h ++++ b/iptables/xtables-multi.h +@@ -20,7 +20,6 @@ extern int xtables_arp_save_main(int, char **); + extern int xtables_eb_main(int, char **); + extern int xtables_eb_restore_main(int, char **); + extern int xtables_eb_save_main(int, char **); +-extern int xtables_config_main(int, char **); + extern int xtables_monitor_main(int, char **); + + extern struct xtables_globals arptables_globals; +-- +2.40.0 + diff --git a/0003-Proper-fix-for-unknown-argument-error-message.patch b/0003-Proper-fix-for-unknown-argument-error-message.patch new file mode 100644 index 0000000..d807c54 --- /dev/null +++ b/0003-Proper-fix-for-unknown-argument-error-message.patch @@ -0,0 +1,148 @@ +From 01c76718d85985625ef53fb6b554bd44742ae6ef Mon Sep 17 00:00:00 2001 +From: Phil Sutter +Date: Wed, 25 Jan 2023 01:51:43 +0100 +Subject: [PATCH] Proper fix for "unknown argument" error message + +While commit 1b8210f848631 kind of fixed the corner-case of invalid +short-options packed with others, it broke error reporting for +long-options. Revert it and deploy a proper solution: + +When passing an invalid short-option, e.g. 'iptables -vaL', getopt_long +sets the variable 'optopt' to the invalid character's value. Use it for +reporting instead of optind if set. + +To distinguish between invalid options and missing option arguments, +ebtables-translate optstring needs adjustment. + +Fixes: 1b8210f848631 ("ebtables: Fix error message for invalid parameters") +Signed-off-by: Phil Sutter +(cherry picked from commit d6eb6a9fd3878ce4fa01f8d4127f1735988bd07b) +--- + .../testcases/iptables/0009-unknown-arg_0 | 31 +++++++++++++++++++ + iptables/xshared.c | 9 ++++-- + iptables/xtables-eb-translate.c | 8 ++--- + iptables/xtables-eb.c | 17 ++++++---- + 4 files changed, 50 insertions(+), 15 deletions(-) + create mode 100755 iptables/tests/shell/testcases/iptables/0009-unknown-arg_0 + +diff --git a/iptables/tests/shell/testcases/iptables/0009-unknown-arg_0 b/iptables/tests/shell/testcases/iptables/0009-unknown-arg_0 +new file mode 100755 +index 0000000000000..ac6e743966196 +--- /dev/null ++++ b/iptables/tests/shell/testcases/iptables/0009-unknown-arg_0 +@@ -0,0 +1,31 @@ ++#!/bin/bash ++ ++rc=0 ++ ++check() { ++ local cmd="$1" ++ local msg="$2" ++ ++ $XT_MULTI $cmd 2>&1 | grep -q "$msg" || { ++ echo "cmd: $XT_MULTI $1" ++ echo "exp: $msg" ++ echo "res: $($XT_MULTI $cmd 2>&1)" ++ rc=1 ++ } ++} ++ ++cmds="iptables ip6tables" ++[[ $XT_MULTI == *xtables-nft-multi ]] && { ++ cmds+=" ebtables" ++ cmds+=" iptables-translate" ++ cmds+=" ip6tables-translate" ++ cmds+=" ebtables-translate" ++} ++ ++for cmd in $cmds; do ++ check "${cmd} --foo" 'unknown option "--foo"' ++ check "${cmd} -A" 'option "-A" requires an argument' ++ check "${cmd} -aL" 'unknown option "-a"' ++done ++ ++exit $rc +diff --git a/iptables/xshared.c b/iptables/xshared.c +index f93529b11a319..ac51fac5ce9ed 100644 +--- a/iptables/xshared.c ++++ b/iptables/xshared.c +@@ -192,9 +192,12 @@ static int command_default(struct iptables_command_state *cs, + if (cs->c == ':') + xtables_error(PARAMETER_PROBLEM, "option \"%s\" " + "requires an argument", cs->argv[optind-1]); +- if (cs->c == '?') +- xtables_error(PARAMETER_PROBLEM, "unknown option " +- "\"%s\"", cs->argv[optind-1]); ++ if (cs->c == '?') { ++ char optoptstr[3] = {'-', optopt, '\0'}; ++ ++ xtables_error(PARAMETER_PROBLEM, "unknown option \"%s\"", ++ optopt ? optoptstr : cs->argv[optind - 1]); ++ } + xtables_error(PARAMETER_PROBLEM, "Unknown arg \"%s\"", optarg); + } + +diff --git a/iptables/xtables-eb-translate.c b/iptables/xtables-eb-translate.c +index 13b6b864a5f24..0c35272051752 100644 +--- a/iptables/xtables-eb-translate.c ++++ b/iptables/xtables-eb-translate.c +@@ -201,7 +201,7 @@ static int do_commandeb_xlate(struct nft_handle *h, int argc, char *argv[], char + printf("nft "); + /* Getopt saves the day */ + while ((c = getopt_long(argc, argv, +- "-A:D:I:N:E:X::L::Z::F::P:Vhi:o:j:c:p:s:d:t:M:", opts, NULL)) != -1) { ++ "-:A:D:I:N:E:X::L::Z::F::P:Vhi:o:j:c:p:s:d:t:M:", opts, NULL)) != -1) { + cs.c = c; + switch (c) { + case 'A': /* Add a rule */ +@@ -491,11 +491,7 @@ static int do_commandeb_xlate(struct nft_handle *h, int argc, char *argv[], char + continue; + default: + ebt_check_inverse2(optarg, argc, argv); +- +- if (ebt_command_default(&cs)) +- xtables_error(PARAMETER_PROBLEM, +- "Unknown argument: '%s'", +- argv[optind - 1]); ++ ebt_command_default(&cs); + + if (command != 'A' && command != 'I' && + command != 'D') +diff --git a/iptables/xtables-eb.c b/iptables/xtables-eb.c +index 7214a767ffe96..412b5cccdc46a 100644 +--- a/iptables/xtables-eb.c ++++ b/iptables/xtables-eb.c +@@ -640,7 +640,16 @@ int ebt_command_default(struct iptables_command_state *cs) + return 0; + } + } +- return 1; ++ if (cs->c == ':') ++ xtables_error(PARAMETER_PROBLEM, "option \"%s\" " ++ "requires an argument", cs->argv[optind - 1]); ++ if (cs->c == '?') { ++ char optoptstr[3] = {'-', optopt, '\0'}; ++ ++ xtables_error(PARAMETER_PROBLEM, "unknown option \"%s\"", ++ optopt ? optoptstr : cs->argv[optind - 1]); ++ } ++ xtables_error(PARAMETER_PROBLEM, "Unknown arg \"%s\"", optarg); + } + + int nft_init_eb(struct nft_handle *h, const char *pname) +@@ -1084,11 +1093,7 @@ int do_commandeb(struct nft_handle *h, int argc, char *argv[], char **table, + continue; + default: + ebt_check_inverse2(optarg, argc, argv); +- +- if (ebt_command_default(&cs)) +- xtables_error(PARAMETER_PROBLEM, +- "Unknown argument: '%s'", +- argv[optind]); ++ ebt_command_default(&cs); + + if (command != 'A' && command != 'I' && + command != 'D' && command != 'C' && command != 14) +-- +2.40.0 + diff --git a/0004-ebtables-Refuse-unselected-targets-options.patch b/0004-ebtables-Refuse-unselected-targets-options.patch new file mode 100644 index 0000000..c41ba45 --- /dev/null +++ b/0004-ebtables-Refuse-unselected-targets-options.patch @@ -0,0 +1,232 @@ +From a53dfa149429c49789947e61c325f9a11e9a83d3 Mon Sep 17 00:00:00 2001 +From: Phil Sutter +Date: Wed, 25 Jan 2023 02:01:56 +0100 +Subject: [PATCH] ebtables: Refuse unselected targets' options + +Unlike legacy, ebtables-nft would allow e.g.: + +| -t nat -A PREROUTING --to-dst fe:ed:00:00:ba:be + +While the result is correct, it may mislead users into believing +multiple targets are possible per rule. Better follow legacy's behaviour +and reject target options unless they have been "enabled" by a previous +'-j' option. + +To achieve this, one needs to distinguish targets from watchers also +attached to 'xtables_targets' and otherwise behaving like regular +matches. Introduce XTABLES_EXT_WATCHER to mark the two. + +The above works already, but error messages are misleading when using +the now unsupported syntax since target options have been merged +already. Solve this by not pre-loading the targets at all, code will +just fall back to loading ad '-j' parsing time as iptables does. + +Note how this also fixes for 'counter' statement being in wrong position +of ebtables-translate output. + +Fixes: fe97f60e5d2a9 ("ebtables-compat: add watchers support") +Signed-off-by: Phil Sutter +(cherry picked from commit 27d37863a486352511dac385bde8f3d20526be5b) +--- + extensions/libebt_dnat.txlate | 12 ++++---- + extensions/libebt_log.c | 1 + + extensions/libebt_mark.txlate | 16 +++++----- + extensions/libebt_nflog.c | 1 + + extensions/libebt_snat.txlate | 8 ++--- + include/xtables.h | 1 + + .../ebtables/0002-ebtables-save-restore_0 | 4 +-- + iptables/xtables-eb.c | 29 +++++++------------ + 8 files changed, 33 insertions(+), 39 deletions(-) + +diff --git a/extensions/libebt_dnat.txlate b/extensions/libebt_dnat.txlate +index 9f305c76c954f..531a22aa3e14f 100644 +--- a/extensions/libebt_dnat.txlate ++++ b/extensions/libebt_dnat.txlate +@@ -1,8 +1,8 @@ +-ebtables-translate -t nat -A PREROUTING -i someport --to-dst de:ad:00:be:ee:ff +-nft 'add rule bridge nat PREROUTING iifname "someport" ether daddr set de:ad:0:be:ee:ff accept counter' ++ebtables-translate -t nat -A PREROUTING -i someport -j dnat --to-dst de:ad:00:be:ee:ff ++nft 'add rule bridge nat PREROUTING iifname "someport" counter ether daddr set de:ad:0:be:ee:ff accept' + +-ebtables-translate -t nat -A PREROUTING -i someport --to-dst de:ad:00:be:ee:ff --dnat-target ACCEPT +-nft 'add rule bridge nat PREROUTING iifname "someport" ether daddr set de:ad:0:be:ee:ff accept counter' ++ebtables-translate -t nat -A PREROUTING -i someport -j dnat --to-dst de:ad:00:be:ee:ff --dnat-target ACCEPT ++nft 'add rule bridge nat PREROUTING iifname "someport" counter ether daddr set de:ad:0:be:ee:ff accept' + +-ebtables-translate -t nat -A PREROUTING -i someport --to-dst de:ad:00:be:ee:ff --dnat-target CONTINUE +-nft 'add rule bridge nat PREROUTING iifname "someport" ether daddr set de:ad:0:be:ee:ff continue counter' ++ebtables-translate -t nat -A PREROUTING -i someport -j dnat --to-dst de:ad:00:be:ee:ff --dnat-target CONTINUE ++nft 'add rule bridge nat PREROUTING iifname "someport" counter ether daddr set de:ad:0:be:ee:ff continue' +diff --git a/extensions/libebt_log.c b/extensions/libebt_log.c +index 045062196d20d..9f8d158956802 100644 +--- a/extensions/libebt_log.c ++++ b/extensions/libebt_log.c +@@ -197,6 +197,7 @@ static int brlog_xlate(struct xt_xlate *xl, + static struct xtables_target brlog_target = { + .name = "log", + .revision = 0, ++ .ext_flags = XTABLES_EXT_WATCHER, + .version = XTABLES_VERSION, + .family = NFPROTO_BRIDGE, + .size = XT_ALIGN(sizeof(struct ebt_log_info)), +diff --git a/extensions/libebt_mark.txlate b/extensions/libebt_mark.txlate +index d006e8ac94008..4ace1a1f5cfde 100644 +--- a/extensions/libebt_mark.txlate ++++ b/extensions/libebt_mark.txlate +@@ -1,11 +1,11 @@ +-ebtables-translate -A INPUT --mark-set 42 +-nft 'add rule bridge filter INPUT meta mark set 0x2a accept counter' ++ebtables-translate -A INPUT -j mark --mark-set 42 ++nft 'add rule bridge filter INPUT counter meta mark set 0x2a accept' + +-ebtables-translate -A INPUT --mark-or 42 --mark-target RETURN +-nft 'add rule bridge filter INPUT meta mark set meta mark or 0x2a return counter' ++ebtables-translate -A INPUT -j mark --mark-or 42 --mark-target RETURN ++nft 'add rule bridge filter INPUT counter meta mark set meta mark or 0x2a return' + +-ebtables-translate -A INPUT --mark-and 42 --mark-target ACCEPT +-nft 'add rule bridge filter INPUT meta mark set meta mark and 0x2a accept counter' ++ebtables-translate -A INPUT -j mark --mark-and 42 --mark-target ACCEPT ++nft 'add rule bridge filter INPUT counter meta mark set meta mark and 0x2a accept' + +-ebtables-translate -A INPUT --mark-xor 42 --mark-target DROP +-nft 'add rule bridge filter INPUT meta mark set meta mark xor 0x2a drop counter' ++ebtables-translate -A INPUT -j mark --mark-xor 42 --mark-target DROP ++nft 'add rule bridge filter INPUT counter meta mark set meta mark xor 0x2a drop' +diff --git a/extensions/libebt_nflog.c b/extensions/libebt_nflog.c +index 115e15da45845..762d6d5d8bbe2 100644 +--- a/extensions/libebt_nflog.c ++++ b/extensions/libebt_nflog.c +@@ -146,6 +146,7 @@ static int brnflog_xlate(struct xt_xlate *xl, + static struct xtables_target brnflog_watcher = { + .name = "nflog", + .revision = 0, ++ .ext_flags = XTABLES_EXT_WATCHER, + .version = XTABLES_VERSION, + .family = NFPROTO_BRIDGE, + .size = XT_ALIGN(sizeof(struct ebt_nflog_info)), +diff --git a/extensions/libebt_snat.txlate b/extensions/libebt_snat.txlate +index 857a6052aed1a..37343d3a14754 100644 +--- a/extensions/libebt_snat.txlate ++++ b/extensions/libebt_snat.txlate +@@ -1,5 +1,5 @@ +-ebtables-translate -t nat -A POSTROUTING -s 0:0:0:0:0:0 -o someport+ --to-source de:ad:00:be:ee:ff +-nft 'add rule bridge nat POSTROUTING oifname "someport*" ether saddr 00:00:00:00:00:00 ether saddr set de:ad:0:be:ee:ff accept counter' ++ebtables-translate -t nat -A POSTROUTING -s 0:0:0:0:0:0 -o someport+ -j snat --to-source de:ad:00:be:ee:ff ++nft 'add rule bridge nat POSTROUTING oifname "someport*" ether saddr 00:00:00:00:00:00 counter ether saddr set de:ad:0:be:ee:ff accept' + +-ebtables-translate -t nat -A POSTROUTING -o someport --to-src de:ad:00:be:ee:ff --snat-target CONTINUE +-nft 'add rule bridge nat POSTROUTING oifname "someport" ether saddr set de:ad:0:be:ee:ff continue counter' ++ebtables-translate -t nat -A POSTROUTING -o someport -j snat --to-src de:ad:00:be:ee:ff --snat-target CONTINUE ++nft 'add rule bridge nat POSTROUTING oifname "someport" counter ether saddr set de:ad:0:be:ee:ff continue' +diff --git a/include/xtables.h b/include/xtables.h +index 4ffc8ec5a17e9..087a1d600f9ae 100644 +--- a/include/xtables.h ++++ b/include/xtables.h +@@ -203,6 +203,7 @@ struct xtables_lmap { + + enum xtables_ext_flags { + XTABLES_EXT_ALIAS = 1 << 0, ++ XTABLES_EXT_WATCHER = 1 << 1, + }; + + struct xt_xlate; +diff --git a/iptables/tests/shell/testcases/ebtables/0002-ebtables-save-restore_0 b/iptables/tests/shell/testcases/ebtables/0002-ebtables-save-restore_0 +index 1091a4e80bebe..b4f9728bb9b6f 100755 +--- a/iptables/tests/shell/testcases/ebtables/0002-ebtables-save-restore_0 ++++ b/iptables/tests/shell/testcases/ebtables/0002-ebtables-save-restore_0 +@@ -38,7 +38,7 @@ $XT_MULTI ebtables -A foo -p IPv6 --ip6-proto tcp -j ACCEPT + + $XT_MULTI ebtables -A foo --limit 100 --limit-burst 42 -j ACCEPT + $XT_MULTI ebtables -A foo --log +-$XT_MULTI ebtables -A foo --mark-set 0x23 --mark-target ACCEPT ++$XT_MULTI ebtables -A foo -j mark --mark-set 0x23 --mark-target ACCEPT + $XT_MULTI ebtables -A foo --nflog + $XT_MULTI ebtables -A foo --pkttype-type multicast -j ACCEPT + $XT_MULTI ebtables -A foo --stp-type config -j ACCEPT +@@ -53,7 +53,7 @@ $XT_MULTI ebtables -A FORWARD -j foo + $XT_MULTI ebtables -N bar + $XT_MULTI ebtables -P bar RETURN + +-$XT_MULTI ebtables -t nat -A PREROUTING --redirect-target ACCEPT ++$XT_MULTI ebtables -t nat -A PREROUTING -j redirect --redirect-target ACCEPT + #$XT_MULTI ebtables -t nat -A PREROUTING --to-src fe:ed:ba:be:00:01 + + $XT_MULTI ebtables -t nat -A OUTPUT -j ACCEPT +diff --git a/iptables/xtables-eb.c b/iptables/xtables-eb.c +index 412b5cccdc46a..3a73e79725489 100644 +--- a/iptables/xtables-eb.c ++++ b/iptables/xtables-eb.c +@@ -468,14 +468,14 @@ static void ebt_load_match(const char *name) + xtables_error(OTHER_PROBLEM, "Can't alloc memory"); + } + +-static void __ebt_load_watcher(const char *name, const char *typename) ++static void ebt_load_watcher(const char *name) + { + struct xtables_target *watcher; + size_t size; + + watcher = xtables_find_target(name, XTF_TRY_LOAD); + if (!watcher) { +- fprintf(stderr, "Unable to load %s %s\n", name, typename); ++ fprintf(stderr, "Unable to load %s watcher\n", name); + return; + } + +@@ -496,16 +496,6 @@ static void __ebt_load_watcher(const char *name, const char *typename) + xtables_error(OTHER_PROBLEM, "Can't alloc memory"); + } + +-static void ebt_load_watcher(const char *name) +-{ +- return __ebt_load_watcher(name, "watcher"); +-} +- +-static void ebt_load_target(const char *name) +-{ +- return __ebt_load_watcher(name, "target"); +-} +- + void ebt_load_match_extensions(void) + { + opts = ebt_original_options; +@@ -522,13 +512,6 @@ void ebt_load_match_extensions(void) + + ebt_load_watcher("log"); + ebt_load_watcher("nflog"); +- +- ebt_load_target("mark"); +- ebt_load_target("dnat"); +- ebt_load_target("snat"); +- ebt_load_target("arpreply"); +- ebt_load_target("redirect"); +- ebt_load_target("standard"); + } + + void ebt_add_match(struct xtables_match *m, +@@ -633,6 +616,9 @@ int ebt_command_default(struct iptables_command_state *cs) + + /* Is it a watcher option? */ + for (t = xtables_targets; t; t = t->next) { ++ if (!(t->ext_flags & XTABLES_EXT_WATCHER)) ++ continue; ++ + if (t->parse && + t->parse(cs->c - t->option_offset, cs->argv, + ebt_invert, &t->tflags, NULL, &t->t)) { +@@ -726,6 +712,11 @@ int do_commandeb(struct nft_handle *h, int argc, char *argv[], char **table, + optind = 0; + opterr = false; + ++ for (t = xtables_targets; t; t = t->next) { ++ t->tflags = 0; ++ t->used = 0; ++ } ++ + /* Getopt saves the day */ + while ((c = getopt_long(argc, argv, EBT_OPTSTRING, + opts, NULL)) != -1) { +-- +2.40.0 + diff --git a/0005-tests-xlate-Properly-split-input-in-replay-mode.patch b/0005-tests-xlate-Properly-split-input-in-replay-mode.patch new file mode 100644 index 0000000..dd58948 --- /dev/null +++ b/0005-tests-xlate-Properly-split-input-in-replay-mode.patch @@ -0,0 +1,31 @@ +From bb7f92a40360b49535dd3675f47cf989755a4978 Mon Sep 17 00:00:00 2001 +From: Phil Sutter +Date: Fri, 3 Feb 2023 18:48:33 +0100 +Subject: [PATCH] tests: xlate: Properly split input in replay mode + +Source command may contain quotes, using shlex.split() does the right +thing there. + +Fixes: 7705b2daa3bdc ("tests: xlate: Use --check to verify replay") +Signed-off-by: Phil Sutter +(cherry picked from commit 914350a4586d2817ca7c4919c53142562f27bdaf) +--- + xlate-test.py | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/xlate-test.py b/xlate-test.py +index 4cb1401b71677..217d2f0062682 100755 +--- a/xlate-test.py ++++ b/xlate-test.py +@@ -64,7 +64,7 @@ xtables_nft_multi = 'xtables-nft-multi' + if sourceline.find(';') >= 0: + sourceline, searchline = sourceline.split(';') + +- srcwords = sourceline.split() ++ srcwords = shlex.split(sourceline) + + srccmd = srcwords[0] + ipt = srccmd.split('-')[0] +-- +2.40.0 + diff --git a/0006-extensions-libebt_redirect-Fix-target-translation.patch b/0006-extensions-libebt_redirect-Fix-target-translation.patch new file mode 100644 index 0000000..b2f5481 --- /dev/null +++ b/0006-extensions-libebt_redirect-Fix-target-translation.patch @@ -0,0 +1,48 @@ +From 75d208e729b3256fdbbf31709215d30064389d47 Mon Sep 17 00:00:00 2001 +From: Phil Sutter +Date: Tue, 31 Jan 2023 22:28:24 +0100 +Subject: [PATCH] extensions: libebt_redirect: Fix target translation + +While EBT_ACCEPT is the default verdict for ebtables targets, omitting +it from translation implicitly converts it into 'continue'. Omit the +non-default EBT_CONTINUE instead. + +Fixes: 24ce7465056ae ("ebtables-compat: add redirect match extension") +Signed-off-by: Phil Sutter +(cherry picked from commit bb6b243c481f90f7dc4a0bd89187ee2bb823f1f6) +--- + extensions/libebt_redirect.c | 2 +- + extensions/libebt_redirect.txlate | 8 ++++++++ + 2 files changed, 9 insertions(+), 1 deletion(-) + create mode 100644 extensions/libebt_redirect.txlate + +diff --git a/extensions/libebt_redirect.c b/extensions/libebt_redirect.c +index 4d4c7a02cea89..389f3ccb53f60 100644 +--- a/extensions/libebt_redirect.c ++++ b/extensions/libebt_redirect.c +@@ -84,7 +84,7 @@ static int brredir_xlate(struct xt_xlate *xl, + const struct ebt_redirect_info *red = (const void*)params->target->data; + + xt_xlate_add(xl, "meta set pkttype host"); +- if (red->target != EBT_ACCEPT) ++ if (red->target != EBT_CONTINUE) + xt_xlate_add(xl, " %s ", brredir_verdict(red->target)); + return 1; + } +diff --git a/extensions/libebt_redirect.txlate b/extensions/libebt_redirect.txlate +new file mode 100644 +index 0000000000000..f0dd5deaf6406 +--- /dev/null ++++ b/extensions/libebt_redirect.txlate +@@ -0,0 +1,8 @@ ++ebtables-translate -t nat -A PREROUTING -d de:ad:00:00:be:ef -j redirect ++nft 'add rule bridge nat PREROUTING ether daddr de:ad:00:00:be:ef counter meta set pkttype host accept' ++ ++ebtables-translate -t nat -A PREROUTING -d de:ad:00:00:be:ef -j redirect --redirect-target RETURN ++nft 'add rule bridge nat PREROUTING ether daddr de:ad:00:00:be:ef counter meta set pkttype host return' ++ ++ebtables-translate -t nat -A PREROUTING -d de:ad:00:00:be:ef -j redirect --redirect-target CONTINUE ++nft 'add rule bridge nat PREROUTING ether daddr de:ad:00:00:be:ef counter meta set pkttype host' +-- +2.40.0 + diff --git a/0007-extensions-libebt_redirect-Fix-for-wrong-syntax-in-t.patch b/0007-extensions-libebt_redirect-Fix-for-wrong-syntax-in-t.patch new file mode 100644 index 0000000..8f8dcf6 --- /dev/null +++ b/0007-extensions-libebt_redirect-Fix-for-wrong-syntax-in-t.patch @@ -0,0 +1,48 @@ +From 345fb0551048b4b3c9f3f0a136c952a4ae5bf262 Mon Sep 17 00:00:00 2001 +From: Phil Sutter +Date: Tue, 31 Jan 2023 23:32:50 +0100 +Subject: [PATCH] extensions: libebt_redirect: Fix for wrong syntax in + translation + +Meta key comes before 'set' in meta statement. + +Fixes: 24ce7465056ae ("ebtables-compat: add redirect match extension") +Signed-off-by: Phil Sutter +(cherry picked from commit 6d1263002c2a9fc6dfa59c764dee767a084d428d) +--- + extensions/libebt_redirect.c | 2 +- + extensions/libebt_redirect.txlate | 6 +++--- + 2 files changed, 4 insertions(+), 4 deletions(-) + +diff --git a/extensions/libebt_redirect.c b/extensions/libebt_redirect.c +index 389f3ccb53f60..7821935e137aa 100644 +--- a/extensions/libebt_redirect.c ++++ b/extensions/libebt_redirect.c +@@ -83,7 +83,7 @@ static int brredir_xlate(struct xt_xlate *xl, + { + const struct ebt_redirect_info *red = (const void*)params->target->data; + +- xt_xlate_add(xl, "meta set pkttype host"); ++ xt_xlate_add(xl, "meta pkttype set host"); + if (red->target != EBT_CONTINUE) + xt_xlate_add(xl, " %s ", brredir_verdict(red->target)); + return 1; +diff --git a/extensions/libebt_redirect.txlate b/extensions/libebt_redirect.txlate +index f0dd5deaf6406..d073ec774c4fa 100644 +--- a/extensions/libebt_redirect.txlate ++++ b/extensions/libebt_redirect.txlate +@@ -1,8 +1,8 @@ + ebtables-translate -t nat -A PREROUTING -d de:ad:00:00:be:ef -j redirect +-nft 'add rule bridge nat PREROUTING ether daddr de:ad:00:00:be:ef counter meta set pkttype host accept' ++nft 'add rule bridge nat PREROUTING ether daddr de:ad:00:00:be:ef counter meta pkttype set host accept' + + ebtables-translate -t nat -A PREROUTING -d de:ad:00:00:be:ef -j redirect --redirect-target RETURN +-nft 'add rule bridge nat PREROUTING ether daddr de:ad:00:00:be:ef counter meta set pkttype host return' ++nft 'add rule bridge nat PREROUTING ether daddr de:ad:00:00:be:ef counter meta pkttype set host return' + + ebtables-translate -t nat -A PREROUTING -d de:ad:00:00:be:ef -j redirect --redirect-target CONTINUE +-nft 'add rule bridge nat PREROUTING ether daddr de:ad:00:00:be:ef counter meta set pkttype host' ++nft 'add rule bridge nat PREROUTING ether daddr de:ad:00:00:be:ef counter meta pkttype set host' +-- +2.40.0 + diff --git a/0008-extensions-libebt_ip-Do-not-use-ip-dscp-for-translat.patch b/0008-extensions-libebt_ip-Do-not-use-ip-dscp-for-translat.patch new file mode 100644 index 0000000..ad5a3ee --- /dev/null +++ b/0008-extensions-libebt_ip-Do-not-use-ip-dscp-for-translat.patch @@ -0,0 +1,50 @@ +From 6177d53b1b5748d64eba68b42b173427815e454f Mon Sep 17 00:00:00 2001 +From: Phil Sutter +Date: Fri, 3 Feb 2023 18:58:36 +0100 +Subject: [PATCH] extensions: libebt_ip: Do not use 'ip dscp' for translation + +Converting from TOS field match to DSCP one is irreversible, so replay +testing is not possible. Use a raw payload expression to produce +something that translates 1:1 back into an 'ip' match. + +Fixes: 03ecffe6c2cc0 ("ebtables-compat: add initial translations") +Signed-off-by: Phil Sutter +(cherry picked from commit 744c56bda974caaa274318d2825b3e43b55bf145) +--- + extensions/libebt_ip.c | 4 ++-- + extensions/libebt_ip.txlate | 2 +- + 2 files changed, 3 insertions(+), 3 deletions(-) + +diff --git a/extensions/libebt_ip.c b/extensions/libebt_ip.c +index fd87dae7e2c62..8b381aa10b5b7 100644 +--- a/extensions/libebt_ip.c ++++ b/extensions/libebt_ip.c +@@ -442,10 +442,10 @@ static int brip_xlate(struct xt_xlate *xl, + brip_xlate_nh(xl, info, EBT_IP_DEST); + + if (info->bitmask & EBT_IP_TOS) { +- xt_xlate_add(xl, "ip dscp "); ++ xt_xlate_add(xl, "@nh,8,8 "); + if (info->invflags & EBT_IP_TOS) + xt_xlate_add(xl, "!= "); +- xt_xlate_add(xl, "0x%02x ", info->tos & 0x3f); /* remove ECN bits */ ++ xt_xlate_add(xl, "0x%02x ", info->tos); + } + if (info->bitmask & EBT_IP_PROTO) { + struct protoent *pe; +diff --git a/extensions/libebt_ip.txlate b/extensions/libebt_ip.txlate +index 75c1db246fb81..562e3157d7b92 100644 +--- a/extensions/libebt_ip.txlate ++++ b/extensions/libebt_ip.txlate +@@ -5,7 +5,7 @@ ebtables-translate -I FORWARD -p ip --ip-dst 10.0.0.1 + nft 'insert rule bridge filter FORWARD ip daddr 10.0.0.1 counter' + + ebtables-translate -I OUTPUT 3 -p ip -o eth0 --ip-tos 0xff +-nft 'insert rule bridge filter OUTPUT oifname "eth0" ip dscp 0x3f counter' ++nft 'insert rule bridge filter OUTPUT oifname "eth0" @nh,8,8 0xff counter' + + ebtables-translate -A FORWARD -p ip --ip-proto tcp --ip-dport 22 + nft 'add rule bridge filter FORWARD tcp dport 22 counter' +-- +2.40.0 + diff --git a/0009-extensions-libebt_ip-Translation-has-to-match-on-eth.patch b/0009-extensions-libebt_ip-Translation-has-to-match-on-eth.patch new file mode 100644 index 0000000..96cb5ad --- /dev/null +++ b/0009-extensions-libebt_ip-Translation-has-to-match-on-eth.patch @@ -0,0 +1,85 @@ +From 1429ad5300d85ae9e3f6114f609afb1ac6808c71 Mon Sep 17 00:00:00 2001 +From: Phil Sutter +Date: Fri, 3 Feb 2023 17:37:40 +0100 +Subject: [PATCH] extensions: libebt_ip: Translation has to match on ether type + +On one hand, nft refuses th expression in bridge family if layer3 +protocol has not been assured by a previous match. On the other, ebt_ip +kernel module will only match on IPv4 packets, so there might be a +functional change in the translation versus the original. + +Instead of just always emitting an 'ether type' match, decide whether +it's actually needed - explicit "ip " payload matches (or +icmp ones) cause implicit creation of a match on IPv4 by nft. + +Fixes: 03ecffe6c2cc0 ("ebtables-compat: add initial translations") +Signed-off-by: Phil Sutter +(cherry picked from commit b860e658200af8fdeced2896a1a6c2f0f0692b70) +--- + extensions/libebt_ip.c | 21 +++++++++++++++++++++ + extensions/libebt_ip.txlate | 6 +++--- + 2 files changed, 24 insertions(+), 3 deletions(-) + +diff --git a/extensions/libebt_ip.c b/extensions/libebt_ip.c +index 8b381aa10b5b7..68f34bff97deb 100644 +--- a/extensions/libebt_ip.c ++++ b/extensions/libebt_ip.c +@@ -432,6 +432,24 @@ static void brip_xlate_nh(struct xt_xlate *xl, + xtables_ipmask_to_numeric(maskp)); + } + ++static bool may_skip_ether_type_dep(uint8_t flags) ++{ ++ /* these convert to "ip (s|d)addr" matches */ ++ if (flags & (EBT_IP_SOURCE | EBT_IP_DEST)) ++ return true; ++ ++ /* icmp match triggers implicit ether type dependency in nft */ ++ if (flags & EBT_IP_ICMP) ++ return true; ++ ++ /* allow if "ip protocol" match is created by brip_xlate() */ ++ if (flags & EBT_IP_PROTO && ++ !(flags & (EBT_IP_SPORT | EBT_IP_DPORT | EBT_IP_ICMP))) ++ return true; ++ ++ return false; ++} ++ + static int brip_xlate(struct xt_xlate *xl, + const struct xt_xlate_mt_params *params) + { +@@ -441,6 +459,9 @@ static int brip_xlate(struct xt_xlate *xl, + brip_xlate_nh(xl, info, EBT_IP_SOURCE); + brip_xlate_nh(xl, info, EBT_IP_DEST); + ++ if (!may_skip_ether_type_dep(info->bitmask)) ++ xt_xlate_add(xl, "ether type ip "); ++ + if (info->bitmask & EBT_IP_TOS) { + xt_xlate_add(xl, "@nh,8,8 "); + if (info->invflags & EBT_IP_TOS) +diff --git a/extensions/libebt_ip.txlate b/extensions/libebt_ip.txlate +index 562e3157d7b92..28996832225cb 100644 +--- a/extensions/libebt_ip.txlate ++++ b/extensions/libebt_ip.txlate +@@ -5,13 +5,13 @@ ebtables-translate -I FORWARD -p ip --ip-dst 10.0.0.1 + nft 'insert rule bridge filter FORWARD ip daddr 10.0.0.1 counter' + + ebtables-translate -I OUTPUT 3 -p ip -o eth0 --ip-tos 0xff +-nft 'insert rule bridge filter OUTPUT oifname "eth0" @nh,8,8 0xff counter' ++nft 'insert rule bridge filter OUTPUT oifname "eth0" ether type ip @nh,8,8 0xff counter' + + ebtables-translate -A FORWARD -p ip --ip-proto tcp --ip-dport 22 +-nft 'add rule bridge filter FORWARD tcp dport 22 counter' ++nft 'add rule bridge filter FORWARD ether type ip tcp dport 22 counter' + + ebtables-translate -A FORWARD -p ip --ip-proto udp --ip-sport 1024:65535 +-nft 'add rule bridge filter FORWARD udp sport 1024-65535 counter' ++nft 'add rule bridge filter FORWARD ether type ip udp sport 1024-65535 counter' + + ebtables-translate -A FORWARD -p ip --ip-proto 253 + nft 'add rule bridge filter FORWARD ip protocol 253 counter' +-- +2.40.0 + diff --git a/0010-xt_sctp-add-the-missing-chunk-types-in-sctp_help.patch b/0010-xt_sctp-add-the-missing-chunk-types-in-sctp_help.patch new file mode 100644 index 0000000..410a831 --- /dev/null +++ b/0010-xt_sctp-add-the-missing-chunk-types-in-sctp_help.patch @@ -0,0 +1,36 @@ +From 94052918c2fd1508afa15a9a83965755d354d69b Mon Sep 17 00:00:00 2001 +From: Xin Long +Date: Tue, 21 Feb 2023 12:19:42 -0500 +Subject: [PATCH] xt_sctp: add the missing chunk types in sctp_help + +Add the missing chunk types in sctp_help(), so that the help cmd can +display these chunk types as below: + + # iptables -p sctp --help + + chunktypes - ... I_DATA RE_CONFIG PAD ... I_FORWARD_TSN ALL NONE + +Fixes: 6b04d9c34e25 ("xt_sctp: support a couple of new chunk types") +Signed-off-by: Xin Long +Signed-off-by: Phil Sutter +(cherry picked from commit f7c8d896f3305471746a8690f73587a65854d8fa) +--- + extensions/libxt_sctp.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/extensions/libxt_sctp.c b/extensions/libxt_sctp.c +index fe5f5621a033d..6e2b2745dcbd5 100644 +--- a/extensions/libxt_sctp.c ++++ b/extensions/libxt_sctp.c +@@ -50,7 +50,7 @@ static void sctp_help(void) + " --dport ...\n" + "[!] --chunk-types (all|any|none) (chunktype[:flags])+ match if all, any or none of\n" + " chunktypes are present\n" +-"chunktypes - DATA INIT INIT_ACK SACK HEARTBEAT HEARTBEAT_ACK ABORT SHUTDOWN SHUTDOWN_ACK ERROR COOKIE_ECHO COOKIE_ACK ECN_ECNE ECN_CWR SHUTDOWN_COMPLETE ASCONF ASCONF_ACK FORWARD_TSN ALL NONE\n"); ++"chunktypes - DATA INIT INIT_ACK SACK HEARTBEAT HEARTBEAT_ACK ABORT SHUTDOWN SHUTDOWN_ACK ERROR COOKIE_ECHO COOKIE_ACK ECN_ECNE ECN_CWR SHUTDOWN_COMPLETE I_DATA RE_CONFIG PAD ASCONF ASCONF_ACK FORWARD_TSN I_FORWARD_TSN ALL NONE\n"); + } + + static const struct option sctp_opts[] = { +-- +2.40.0 + diff --git a/0011-include-Add-missing-linux-netfilter-xt_LOG.h.patch b/0011-include-Add-missing-linux-netfilter-xt_LOG.h.patch new file mode 100644 index 0000000..e0915f5 --- /dev/null +++ b/0011-include-Add-missing-linux-netfilter-xt_LOG.h.patch @@ -0,0 +1,101 @@ +From 3311bf0d0fefd845d8d1d01b178bcd6701473a43 Mon Sep 17 00:00:00 2001 +From: Phil Sutter +Date: Wed, 22 Feb 2023 16:36:16 +0100 +Subject: [PATCH] include: Add missing linux/netfilter/xt_LOG.h + +When merging IP-version-specific LOG extensions, a dependency to that +header was introduced without caching it. Fix this and drop the now +unused ip{,6}t_LOG.h files. + +Reported-by: Thomas Devoogdt +Fixes: 87e4f1bf0b87b ("extensions: libip*t_LOG: Merge extensions") +Signed-off-by: Phil Sutter +(cherry picked from commit 8030e5444681e16ac2f481ddad73e33fab376147) +--- + include/linux/netfilter/xt_LOG.h | 20 ++++++++++++++++++++ + include/linux/netfilter_ipv4/ipt_LOG.h | 19 ------------------- + include/linux/netfilter_ipv6/ip6t_LOG.h | 19 ------------------- + 3 files changed, 20 insertions(+), 38 deletions(-) + create mode 100644 include/linux/netfilter/xt_LOG.h + delete mode 100644 include/linux/netfilter_ipv4/ipt_LOG.h + delete mode 100644 include/linux/netfilter_ipv6/ip6t_LOG.h + +diff --git a/include/linux/netfilter/xt_LOG.h b/include/linux/netfilter/xt_LOG.h +new file mode 100644 +index 0000000000000..167d4ddd2476b +--- /dev/null ++++ b/include/linux/netfilter/xt_LOG.h +@@ -0,0 +1,20 @@ ++/* SPDX-License-Identifier: GPL-2.0 WITH Linux-syscall-note */ ++#ifndef _XT_LOG_H ++#define _XT_LOG_H ++ ++/* make sure not to change this without changing nf_log.h:NF_LOG_* (!) */ ++#define XT_LOG_TCPSEQ 0x01 /* Log TCP sequence numbers */ ++#define XT_LOG_TCPOPT 0x02 /* Log TCP options */ ++#define XT_LOG_IPOPT 0x04 /* Log IP options */ ++#define XT_LOG_UID 0x08 /* Log UID owning local socket */ ++#define XT_LOG_NFLOG 0x10 /* Unsupported, don't reuse */ ++#define XT_LOG_MACDECODE 0x20 /* Decode MAC header */ ++#define XT_LOG_MASK 0x2f ++ ++struct xt_log_info { ++ unsigned char level; ++ unsigned char logflags; ++ char prefix[30]; ++}; ++ ++#endif /* _XT_LOG_H */ +diff --git a/include/linux/netfilter_ipv4/ipt_LOG.h b/include/linux/netfilter_ipv4/ipt_LOG.h +deleted file mode 100644 +index dcdbadf9fd4a9..0000000000000 +--- a/include/linux/netfilter_ipv4/ipt_LOG.h ++++ /dev/null +@@ -1,19 +0,0 @@ +-#ifndef _IPT_LOG_H +-#define _IPT_LOG_H +- +-/* make sure not to change this without changing netfilter.h:NF_LOG_* (!) */ +-#define IPT_LOG_TCPSEQ 0x01 /* Log TCP sequence numbers */ +-#define IPT_LOG_TCPOPT 0x02 /* Log TCP options */ +-#define IPT_LOG_IPOPT 0x04 /* Log IP options */ +-#define IPT_LOG_UID 0x08 /* Log UID owning local socket */ +-#define IPT_LOG_NFLOG 0x10 /* Unsupported, don't reuse */ +-#define IPT_LOG_MACDECODE 0x20 /* Decode MAC header */ +-#define IPT_LOG_MASK 0x2f +- +-struct ipt_log_info { +- unsigned char level; +- unsigned char logflags; +- char prefix[30]; +-}; +- +-#endif /*_IPT_LOG_H*/ +diff --git a/include/linux/netfilter_ipv6/ip6t_LOG.h b/include/linux/netfilter_ipv6/ip6t_LOG.h +deleted file mode 100644 +index 9dd5579e02ec7..0000000000000 +--- a/include/linux/netfilter_ipv6/ip6t_LOG.h ++++ /dev/null +@@ -1,19 +0,0 @@ +-#ifndef _IP6T_LOG_H +-#define _IP6T_LOG_H +- +-/* make sure not to change this without changing netfilter.h:NF_LOG_* (!) */ +-#define IP6T_LOG_TCPSEQ 0x01 /* Log TCP sequence numbers */ +-#define IP6T_LOG_TCPOPT 0x02 /* Log TCP options */ +-#define IP6T_LOG_IPOPT 0x04 /* Log IP options */ +-#define IP6T_LOG_UID 0x08 /* Log UID owning local socket */ +-#define IP6T_LOG_NFLOG 0x10 /* Unsupported, don't use */ +-#define IP6T_LOG_MACDECODE 0x20 /* Decode MAC header */ +-#define IP6T_LOG_MASK 0x2f +- +-struct ip6t_log_info { +- unsigned char level; +- unsigned char logflags; +- char prefix[30]; +-}; +- +-#endif /*_IPT_LOG_H*/ +-- +2.40.0 + diff --git a/0012-nft-restore-Fix-for-deletion-of-new-referenced-rule.patch b/0012-nft-restore-Fix-for-deletion-of-new-referenced-rule.patch new file mode 100644 index 0000000..8b20709 --- /dev/null +++ b/0012-nft-restore-Fix-for-deletion-of-new-referenced-rule.patch @@ -0,0 +1,67 @@ +From 1d37530ed4a9ece32ed94faa916845a883f8fd05 Mon Sep 17 00:00:00 2001 +From: Phil Sutter +Date: Tue, 28 Feb 2023 18:09:25 +0100 +Subject: [PATCH] nft-restore: Fix for deletion of new, referenced rule + +Combining multiple corner-cases here: + +* Insert a rule before another new one which is not the first. Triggers + NFTNL_RULE_ID assignment of the latter. + +* Delete the referenced new rule in the same batch again. Causes + overwriting of the previously assigned RULE_ID. + +Consequently, iptables-nft-restore fails during *insert*, because the +reference is dangling. + +Reported-by: Eric Garver +Fixes: 760b35b46e4cc ("nft: Fix for add and delete of same rule in single batch") +Signed-off-by: Phil Sutter +Tested-by: Eric Garver +(cherry picked from commit 5fd85822bd12a02f1a921243f605fc6238d705b4) +--- + iptables/nft.c | 3 ++- + .../ipt-restore/0003-restore-ordering_0 | 16 ++++++++++++++++ + 2 files changed, 18 insertions(+), 1 deletion(-) + +diff --git a/iptables/nft.c b/iptables/nft.c +index 63468cf3b1344..5896fd410ca78 100644 +--- a/iptables/nft.c ++++ b/iptables/nft.c +@@ -2343,7 +2343,8 @@ static int __nft_rule_del(struct nft_handle *h, struct nftnl_rule *r) + + nftnl_rule_list_del(r); + +- if (!nftnl_rule_get_u64(r, NFTNL_RULE_HANDLE)) ++ if (!nftnl_rule_get_u64(r, NFTNL_RULE_HANDLE) && ++ !nftnl_rule_get_u32(r, NFTNL_RULE_ID)) + nftnl_rule_set_u32(r, NFTNL_RULE_ID, ++h->rule_id); + + obj = batch_rule_add(h, NFT_COMPAT_RULE_DELETE, r); +diff --git a/iptables/tests/shell/testcases/ipt-restore/0003-restore-ordering_0 b/iptables/tests/shell/testcases/ipt-restore/0003-restore-ordering_0 +index 3f1d229e915ff..5482b7ea17298 100755 +--- a/iptables/tests/shell/testcases/ipt-restore/0003-restore-ordering_0 ++++ b/iptables/tests/shell/testcases/ipt-restore/0003-restore-ordering_0 +@@ -123,3 +123,19 @@ EXPECT='-A FORWARD -m comment --comment "rule 1" -j ACCEPT + -A FORWARD -m comment --comment "rule 3" -j ACCEPT' + + diff -u -Z <(echo -e "$EXPECT") <(ipt_show) ++ ++# test adding, referencing and deleting the same rule in a batch ++ ++$XT_MULTI iptables-restore < +Date: Mon, 3 Apr 2023 23:13:47 +0200 +Subject: [PATCH] ip6tables: Fix checking existence of rule + +Pass the proper entry size when creating a match mask for checking the +existence of a rule. Failing to do so causes wrong results. + +Reported-by: Jonathan Caicedo +Fixes: eb2546a846776 ("xshared: Share make_delete_mask() between ip{,6}tables") +Signed-off-by: Markus Boehme +Signed-off-by: Phil Sutter +(cherry picked from commit 78850e7dba64a949c440dbdbe557f59409c6db48) +--- + iptables/ip6tables.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/iptables/ip6tables.c b/iptables/ip6tables.c +index 345af4519bfe7..9afc32c1a21ed 100644 +--- a/iptables/ip6tables.c ++++ b/iptables/ip6tables.c +@@ -331,7 +331,7 @@ check_entry(const xt_chainlabel chain, struct ip6t_entry *fw, + int ret = 1; + unsigned char *mask; + +- mask = make_delete_mask(matches, target, sizeof(fw)); ++ mask = make_delete_mask(matches, target, sizeof(*fw)); + for (i = 0; i < nsaddrs; i++) { + fw->ipv6.src = saddrs[i]; + fw->ipv6.smsk = smasks[i]; +-- +2.40.0 + diff --git a/0014-nft-shared-Drop-unused-include.patch b/0014-nft-shared-Drop-unused-include.patch new file mode 100644 index 0000000..c4274ca --- /dev/null +++ b/0014-nft-shared-Drop-unused-include.patch @@ -0,0 +1,29 @@ +From 1bf20a3bd929060cb9afdd798292f0463243e26d Mon Sep 17 00:00:00 2001 +From: Phil Sutter +Date: Wed, 29 Mar 2023 16:22:16 +0200 +Subject: [PATCH] nft-shared: Drop unused include + +Code does not refer to struct xt_comment_info anymore. + +Fixes: 3bb497c61d743 ("xtables: Fix for deleting rules with comment") +Signed-off-by: Phil Sutter +(cherry picked from commit 465470184950d9035dcd1101c1f413f8a2051427) +--- + iptables/nft-shared.c | 1 - + 1 file changed, 1 deletion(-) + +diff --git a/iptables/nft-shared.c b/iptables/nft-shared.c +index 4a7b5406892c4..4ba44a4aa4d17 100644 +--- a/iptables/nft-shared.c ++++ b/iptables/nft-shared.c +@@ -22,7 +22,6 @@ + #include + + #include +-#include + #include + #include + #include +-- +2.40.0 + diff --git a/0015-arptables-Fix-parsing-of-inverted-arp-operation-matc.patch b/0015-arptables-Fix-parsing-of-inverted-arp-operation-matc.patch new file mode 100644 index 0000000..5474f8a --- /dev/null +++ b/0015-arptables-Fix-parsing-of-inverted-arp-operation-matc.patch @@ -0,0 +1,31 @@ +From 9a4b3bde58819e55a2d852800e87e66629a87081 Mon Sep 17 00:00:00 2001 +From: Phil Sutter +Date: Fri, 28 Apr 2023 14:33:43 +0200 +Subject: [PATCH] arptables: Fix parsing of inverted 'arp operation' match + +The wrong bit was set in 'invflags', probably due to copy'n'paste from +the previous case. + +Fixes: 84909d171585d ("xtables: bootstrap ARP compatibility layer for nftables") +Signed-off-by: Phil Sutter +(cherry picked from commit 092e4b022152addc94524e2ba0cb608dac1a3a08) +--- + iptables/nft-arp.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/iptables/nft-arp.c b/iptables/nft-arp.c +index 210f43d2cefbe..8fae5adc50216 100644 +--- a/iptables/nft-arp.c ++++ b/iptables/nft-arp.c +@@ -244,7 +244,7 @@ static void nft_arp_parse_payload(struct nft_xt_ctx *ctx, + fw->arp.arhln = ar_hln; + fw->arp.arhln_mask = 0xff; + if (inv) +- fw->arp.invflags |= IPT_INV_ARPOP; ++ fw->arp.invflags |= IPT_INV_ARPHLN; + break; + case offsetof(struct arphdr, ar_pln): + get_cmp_data(e, &ar_pln, sizeof(ar_pln), &inv); +-- +2.40.0 + diff --git a/0016-arptables-Don-t-omit-standard-matches-if-inverted.patch b/0016-arptables-Don-t-omit-standard-matches-if-inverted.patch new file mode 100644 index 0000000..1efb846 --- /dev/null +++ b/0016-arptables-Don-t-omit-standard-matches-if-inverted.patch @@ -0,0 +1,42 @@ +From a900100d6d4be7c52e4cfd1ab06ce3ac626d71a1 Mon Sep 17 00:00:00 2001 +From: Phil Sutter +Date: Fri, 28 Apr 2023 14:37:47 +0200 +Subject: [PATCH] arptables: Don't omit standard matches if inverted + +Inverted --h-len and --h-type matches were omitted from output by +accident if they matched on their standard value. + +Fixes: 84331e3ed3f8e ("arptables-nft: Don't print default h-len/h-type values") +Signed-off-by: Phil Sutter +(cherry picked from commit 79f93b0943fa0e46ba29bb476362634509eb594e) +--- + iptables/nft-arp.c | 6 ++++-- + 1 file changed, 4 insertions(+), 2 deletions(-) + +diff --git a/iptables/nft-arp.c b/iptables/nft-arp.c +index 8fae5adc50216..df3ad430cf701 100644 +--- a/iptables/nft-arp.c ++++ b/iptables/nft-arp.c +@@ -408,7 +408,8 @@ static void nft_arp_print_rule_details(const struct iptables_command_state *cs, + + after_devdst: + +- if (fw->arp.arhln_mask != 255 || fw->arp.arhln != 6) { ++ if (fw->arp.arhln_mask != 255 || fw->arp.arhln != 6 || ++ fw->arp.invflags & IPT_INV_ARPHLN) { + printf("%s%s", sep, fw->arp.invflags & IPT_INV_ARPHLN + ? "! " : ""); + printf("--h-length %d", fw->arp.arhln); +@@ -432,7 +433,8 @@ static void nft_arp_print_rule_details(const struct iptables_command_state *cs, + sep = " "; + } + +- if (fw->arp.arhrd_mask != 65535 || fw->arp.arhrd != htons(1)) { ++ if (fw->arp.arhrd_mask != 65535 || fw->arp.arhrd != htons(1) || ++ fw->arp.invflags & IPT_INV_ARPHRD) { + uint16_t tmp = ntohs(fw->arp.arhrd); + + printf("%s%s", sep, fw->arp.invflags & IPT_INV_ARPHRD +-- +2.40.0 + diff --git a/0017-xshared-Fix-parsing-of-option-arguments-in-same-word.patch b/0017-xshared-Fix-parsing-of-option-arguments-in-same-word.patch new file mode 100644 index 0000000..9c5cbd2 --- /dev/null +++ b/0017-xshared-Fix-parsing-of-option-arguments-in-same-word.patch @@ -0,0 +1,211 @@ +From 174ef8164bc3b1f9454f77b3747f1591ea5b5a9f Mon Sep 17 00:00:00 2001 +From: Phil Sutter +Date: Fri, 28 Apr 2023 14:41:08 +0200 +Subject: [PATCH] xshared: Fix parsing of option arguments in same word + +When merging commandline parsers, a decision between 'argv[optind - 1]' +and 'optarg' had to be made in some spots. While the implementation of +check_inverse() required the former, use of the latter allows for the +common syntax of '--opt=arg' or even '-oarg' as 'optarg' will point at +the suffix while 'argv[optind - 1]' will just point at the following +option. + +Fix the mess by making check_inverse() update optarg pointer if needed +so calling code may refer to and always correct 'optarg'. + +Fixes: 0af80a91b0a98 ("nft: Merge xtables-arp-standalone.c into xtables-standalone.c") +Closes: https://bugzilla.netfilter.org/show_bug.cgi?id=1677 +Signed-off-by: Phil Sutter +(cherry picked from commit 90a7a183a208b691810b8519cc57d3d9d3b7eb60) +--- + extensions/libarpt_standard.t | 2 ++ + extensions/libxt_standard.t | 3 ++ + iptables/xshared.c | 61 +++++++++++++++++------------------ + 3 files changed, 35 insertions(+), 31 deletions(-) + +diff --git a/extensions/libarpt_standard.t b/extensions/libarpt_standard.t +index e84a00b780488..007fa2b8335e8 100644 +--- a/extensions/libarpt_standard.t ++++ b/extensions/libarpt_standard.t +@@ -12,3 +12,5 @@ + -i lo --destination-mac 11:22:33:44:55:66;-i lo --dst-mac 11:22:33:44:55:66;OK + --source-mac Unicast;--src-mac 00:00:00:00:00:00/01:00:00:00:00:00;OK + ! --src-mac Multicast;! --src-mac 01:00:00:00:00:00/01:00:00:00:00:00;OK ++--src-mac=01:02:03:04:05:06 --dst-mac=07:08:09:0A:0B:0C --h-length=6 --opcode=Request --h-type=Ethernet --proto-type=ipv4;--src-mac 01:02:03:04:05:06 --dst-mac 07:08:09:0a:0b:0c --opcode 1 --proto-type 0x800;OK ++--src-mac ! 01:02:03:04:05:06 --dst-mac ! 07:08:09:0A:0B:0C --h-length ! 6 --opcode ! Request --h-type ! Ethernet --proto-type ! ipv4;! --src-mac 01:02:03:04:05:06 ! --dst-mac 07:08:09:0a:0b:0c ! --h-length 6 ! --opcode 1 ! --h-type 1 ! --proto-type 0x800;OK +diff --git a/extensions/libxt_standard.t b/extensions/libxt_standard.t +index 56d6da2e5884e..6ed978e442b80 100644 +--- a/extensions/libxt_standard.t ++++ b/extensions/libxt_standard.t +@@ -21,3 +21,6 @@ + -s 10.11.12.13/255.128.0.0;-s 10.0.0.0/9;OK + -s 10.11.12.13/255.0.255.0;-s 10.0.12.0/255.0.255.0;OK + -s 10.11.12.13/255.0.12.0;-s 10.0.12.0/255.0.12.0;OK ++:FORWARD ++--protocol=tcp --source=1.2.3.4 --destination=5.6.7.8/32 --in-interface=eth0 --out-interface=eth1 --jump=ACCEPT;-s 1.2.3.4/32 -d 5.6.7.8/32 -i eth0 -o eth1 -p tcp -j ACCEPT;OK ++-ptcp -s1.2.3.4 -d5.6.7.8/32 -ieth0 -oeth1 -jACCEPT;-s 1.2.3.4/32 -d 5.6.7.8/32 -i eth0 -o eth1 -p tcp -j ACCEPT;OK +diff --git a/iptables/xshared.c b/iptables/xshared.c +index ac51fac5ce9ed..17aed04e02b09 100644 +--- a/iptables/xshared.c ++++ b/iptables/xshared.c +@@ -1318,7 +1318,7 @@ static void check_empty_interface(struct xtables_args *args, const char *arg) + } + + static void check_inverse(struct xtables_args *args, const char option[], +- bool *invert, int *optidx, int argc) ++ bool *invert, int argc, char **argv) + { + switch (args->family) { + case NFPROTO_ARP: +@@ -1337,12 +1337,11 @@ static void check_inverse(struct xtables_args *args, const char option[], + xtables_error(PARAMETER_PROBLEM, + "Multiple `!' flags not allowed"); + *invert = true; +- if (optidx) { +- *optidx = *optidx + 1; +- if (argc && *optidx > argc) +- xtables_error(PARAMETER_PROBLEM, +- "no argument following `!'"); +- } ++ optind++; ++ if (optind > argc) ++ xtables_error(PARAMETER_PROBLEM, "no argument following `!'"); ++ ++ optarg = argv[optind - 1]; + } + + static const char *optstring_lookup(int family) +@@ -1555,16 +1554,16 @@ void do_parse(int argc, char *argv[], + * Option selection + */ + case 'p': +- check_inverse(args, optarg, &invert, &optind, argc); ++ check_inverse(args, optarg, &invert, argc, argv); + set_option(&cs->options, OPT_PROTOCOL, + &args->invflags, invert); + + /* Canonicalize into lower case */ +- for (cs->protocol = argv[optind - 1]; ++ for (cs->protocol = optarg; + *cs->protocol; cs->protocol++) + *cs->protocol = tolower(*cs->protocol); + +- cs->protocol = argv[optind - 1]; ++ cs->protocol = optarg; + args->proto = xtables_parse_protocol(cs->protocol); + + if (args->proto == 0 && +@@ -1578,17 +1577,17 @@ void do_parse(int argc, char *argv[], + break; + + case 's': +- check_inverse(args, optarg, &invert, &optind, argc); ++ check_inverse(args, optarg, &invert, argc, argv); + set_option(&cs->options, OPT_SOURCE, + &args->invflags, invert); +- args->shostnetworkmask = argv[optind - 1]; ++ args->shostnetworkmask = optarg; + break; + + case 'd': +- check_inverse(args, optarg, &invert, &optind, argc); ++ check_inverse(args, optarg, &invert, argc, argv); + set_option(&cs->options, OPT_DESTINATION, + &args->invflags, invert); +- args->dhostnetworkmask = argv[optind - 1]; ++ args->dhostnetworkmask = optarg; + break; + + #ifdef IPT_F_GOTO +@@ -1601,71 +1600,71 @@ void do_parse(int argc, char *argv[], + #endif + + case 2:/* src-mac */ +- check_inverse(args, optarg, &invert, &optind, argc); ++ check_inverse(args, optarg, &invert, argc, argv); + set_option(&cs->options, OPT_S_MAC, &args->invflags, + invert); +- args->src_mac = argv[optind - 1]; ++ args->src_mac = optarg; + break; + + case 3:/* dst-mac */ +- check_inverse(args, optarg, &invert, &optind, argc); ++ check_inverse(args, optarg, &invert, argc, argv); + set_option(&cs->options, OPT_D_MAC, &args->invflags, + invert); +- args->dst_mac = argv[optind - 1]; ++ args->dst_mac = optarg; + break; + + case 'l':/* hardware length */ +- check_inverse(args, optarg, &invert, &optind, argc); ++ check_inverse(args, optarg, &invert, argc, argv); + set_option(&cs->options, OPT_H_LENGTH, &args->invflags, + invert); +- args->arp_hlen = argv[optind - 1]; ++ args->arp_hlen = optarg; + break; + + case 8: /* was never supported, not even in arptables-legacy */ + xtables_error(PARAMETER_PROBLEM, "not supported"); + case 4:/* opcode */ +- check_inverse(args, optarg, &invert, &optind, argc); ++ check_inverse(args, optarg, &invert, argc, argv); + set_option(&cs->options, OPT_OPCODE, &args->invflags, + invert); +- args->arp_opcode = argv[optind - 1]; ++ args->arp_opcode = optarg; + break; + + case 5:/* h-type */ +- check_inverse(args, optarg, &invert, &optind, argc); ++ check_inverse(args, optarg, &invert, argc, argv); + set_option(&cs->options, OPT_H_TYPE, &args->invflags, + invert); +- args->arp_htype = argv[optind - 1]; ++ args->arp_htype = optarg; + break; + + case 6:/* proto-type */ +- check_inverse(args, optarg, &invert, &optind, argc); ++ check_inverse(args, optarg, &invert, argc, argv); + set_option(&cs->options, OPT_P_TYPE, &args->invflags, + invert); +- args->arp_ptype = argv[optind - 1]; ++ args->arp_ptype = optarg; + break; + + case 'j': + set_option(&cs->options, OPT_JUMP, &args->invflags, + invert); +- command_jump(cs, argv[optind - 1]); ++ command_jump(cs, optarg); + break; + + case 'i': + check_empty_interface(args, optarg); +- check_inverse(args, optarg, &invert, &optind, argc); ++ check_inverse(args, optarg, &invert, argc, argv); + set_option(&cs->options, OPT_VIANAMEIN, + &args->invflags, invert); +- xtables_parse_interface(argv[optind - 1], ++ xtables_parse_interface(optarg, + args->iniface, + args->iniface_mask); + break; + + case 'o': + check_empty_interface(args, optarg); +- check_inverse(args, optarg, &invert, &optind, argc); ++ check_inverse(args, optarg, &invert, argc, argv); + set_option(&cs->options, OPT_VIANAMEOUT, + &args->invflags, invert); +- xtables_parse_interface(argv[optind - 1], ++ xtables_parse_interface(optarg, + args->outiface, + args->outiface_mask); + break; +-- +2.40.0 + diff --git a/arptables-helper b/arptables-nft-helper similarity index 100% rename from arptables-helper rename to arptables-nft-helper diff --git a/arptables.service b/arptables.service deleted file mode 100644 index df6c7d6..0000000 --- a/arptables.service +++ /dev/null @@ -1,12 +0,0 @@ -[Unit] -Description=Automates a packet filtering firewall with arptables -After=network.target - -[Service] -Type=oneshot -ExecStart=/usr/libexec/arptables-helper start -ExecStop=/usr/libexec/arptables-helper stop -RemainAfterExit=yes - -[Install] -WantedBy=multi-user.target diff --git a/coreteam-gpg-key-0xD70D1A666ACF2B21.txt b/coreteam-gpg-key-0xD70D1A666ACF2B21.txt deleted file mode 100644 index cd4a35b..0000000 --- a/coreteam-gpg-key-0xD70D1A666ACF2B21.txt +++ /dev/null @@ -1,64 +0,0 @@ ------BEGIN PGP PUBLIC KEY BLOCK----- - -mQINBGcLlIQBEADH+pWx2d5XgY2JCOHTVaOpbNlNfp1k9Ul0W5zaZ7EFHIGSj06E -o3+OM0eI6+d51PnqwRE+WbV4T3ooGnfgXN4fmKgq2TwkxlhKeFSzNGMuzzuoEwD+ -2cvSF9VIrwif1o9oa9KMNfKTY/qjuWZS0QWZ08thPAf/tWpoaA3gaqYQUshj5G3w -nTMdYlHUj7wkZCMg63tDygAe/7fDT3zurKCMbFoyiyQkp7V1SLxZpvuyuyPH6HtQ -P5xcbXsp5ots0BgN+BplMX89DrspxJXqi7AsTf4QnC78KbchMJJxLKZQS759dQHF -qHUTb3YdlxXFou6Si5LiBzvmqBRFj6m/WV1a8mDy5fPDkOLoTCUFHLmgvYHPJdtK -5EqNkwYAbSnZKe9aSeVa4XhaZqyyQb9vIsKyOnwdJ/l222J95qHQapZSLcRdqgQz -ZgxuEdOHacEaJ1IJ21CE8EtJfFA5DMZtkZNIGF3OFlXhw7YxJoPgsodtlVspQsfX -u2FGP9yg0fd4zLgHnotKqfJQ9ZjMB6bbJUd6Au9jv0SiM+kVGeVfyaaX7TDeQ3TT -/e44uFvkHkbYFQPcqsTalxtre6v7pMG2iu2mbkhQOC7qbL5MKMSdA93w/lF7w20b -cwyDavEoKk9vgDjSkVjaffvdy4cESa5JY4lM4ZmzoujnAZMwbzQeGcBtqQARAQAB -tCxOZXRmaWx0ZXIgQ29yZSBUZWFtIDxjb3JldGVhbUBuZXRmaWx0ZXIub3JnPokC -VAQTAQoAPhYhBIxfcUahdXpl4kIqlNcNGmZqzyshBQJnC5SEAhsDBQkHhM4ABQsJ -CAcCBhUKCQgLAgQWAgMBAh4BAheAAAoJENcNGmZqzyshRE4P/AknD3DAWuCT7x7L -LFIUCkfl7WUou9zMQKy62JRK/+/lNyG1dkmvBu7XWLl/+IRv1uIb25I4xwaze6GF -8yhZDNXZLhUjComr864fMEdKNdXInAClLRNY0InkFmHw/SizvwDld4PgsLzoS+qL -5JY4FBlYEnd4wlIwH/w3gPycmdmQNVOjeWJhDrYKGLnjolpGRQPYRME4kjasWPbK -AWG/lpINQEB1DgtK8e6kcbUA8wSU6MMEsJjPY0o7lr9NvPfRpPXq34LjoFUXk3Hi -Bt8OuVVMo+wTmlZWkXdknFKS4IPVxUA53oJOVMFW8divmF/l676KBogSnczoX4vR -VW8sgDEKqb0NicKWJ2Fou+/KueY5OXsO8aZrZtXOsXIAMberdrNDYhyTUSYF8mZF -RdL6Jcm5GbQB/zOQElgzMwPQq5AD7SkziMzGOusWjqGmu9qphed/FimVbyRhMl5B -uDvGHthhy1KlPkqVcddN6i3/Kd/AMqXAuWMZH9FXJkUUWe+VAyeNHfEuBtSK2rqE -zf8TYGg5Gz+oNspWuqEyWUwoH7eQkRx2GIbwu2rwcIzrh8L0rsyu+6FNNHnQfnNq -ytbE888dxKkXeJ5T09Pp/hPwkNM8X8ZLcTTsAknrvqLNp2As49dP6iJwysfYLf/v -3Cyvz23JNeSQiTcC4YfKLs4LtCFkiQIzBBABCgAdFiEEN9lkrMBJgcdVAPub1V2X -iooUIOQFAmcLlJ0ACgkQ1V2XiooUIOQGJRAAsz/jYoNkSAhzvrY1t/5kSaa3Hyqi -wpaJNIb6YCNT9JFlEvfsIlikjK28I+LNqVrWoLZyX1np8h0AGfNUPo/rLzVXzqZ/ -UHZi5AjzXM6BVnR84LahFVVLISBtjt3DvY4xvl8cIh03ShJe/yAKIXZUbxXevtnj -M0/5bLaLjlVf3KldR+gFjUaTT1nxfkQnzxbk2yKe+1tuQzFsYPLG9Elzyagb4QYm -97CTxim3QcO0qWweoeusBqCkh7qD/ght76JrSnzq859XS//2jaq3A5ZsX5UJk5/E -FkzL4zersQZwQE10BByBBJbxC8DzMuGeV+eTVVHKU81cEnzZFxfyOtQBD+oHBauW -IC/v509TiH4qhZshJwcznsDZK1xAxxm3mryVtHbfSDSqzc5r/kNQt9mijD6wdsRb -0yQy1P2xkk1zyvOw3BRI2NVXq6+642cp21tjsY136JT/3a6KwIlIIdzIUqejbLoF -GgGZPJiQXthfmLpDgvduD6YgaSHyhtJesX3SIGvYBdCGT69blrB7lHazYRE/xKNu -bhnVzsaWlOXg52ChAMzsAAi5DV1669xUqRgj7zJHUq72bItZWdAvDSTIrQB4z7u8 -QW+XZsveWM2sKjzpLZjQaxdS7dFvGepYY5liA01w7Bx2lU75ejgaWrm/hlaT//RD -Al9IQzw14mOtm0e5Ag0EZwuUhAEQANmO+fv67llu3nOZh9mcTbKa0MTT6cNjpEVU -3MDImbN7pKTc/P+s6TVYBYn1q1U0XTXQlfh2HGdrLebAOdWW0Wcz4Kj9oOlRHOAR -yq3mRzb9hiCB89mJcw5xNIn83d5L/IJqONSaVLKnTwfwnTVaCJYuF5yIqDMOSXgS -C3sbGLx/yEchAhQEWUG8nm9WTybFfq98mFrHEKRGsSgfCHq6KMNn9NuhW149ZK+K -klPXZqFyDoRHdyivt9j9hfA0lr4t6sfXEfJedzjNO2f0Z8r2sQhmw3ykYDkzEF8I -zkgiik1Ke4+TmpD/4uL/hfgbkoVxZV6gI3M9rqs5o1glAuSFjsrGyog1EkUXplST -Qn4ea/vQ6t1iBkTb2r3qzhK+VL7GWlvZa9DGq8btNAiOjKKqa0+3zRTXyPJAdMQM -X+FBAhmaHJoylArEHdzv5haB7rv0aGjKV4O1ifonSGE2pllmSDbTO3exIeslLgDh -5GqVmQW30K5JvecKnb871c0utzRLHBF34HOYgRWBcl18DGD+SzXKj1//+4AatcAB -woNJHTEh6N3/mD3fJyWkyMwLJzo1x43Pmm1DkzioO9VMSxG7ReaH9WRDty3R83gT -njEI0CDkG7m0nXctrsDcmBCYMSnvriWVr7kNYQ9tSi9WUa8Cs0xCmy49fF+7ihIl -yANR2aMrABEBAAGJAjwEGAEKACYWIQSMX3FGoXV6ZeJCKpTXDRpmas8rIQUCZwuU -hAIbDAUJB4TOAAAKCRDXDRpmas8rIZPuD/4qYhAdmCtaicOjeuMI0EhKA0O0cnXv -BRwKXKGISZ6bt/f5fify78NQ4VdQzcpsRk1VvaEHRF5H+qxCQJ8MdzKcYpolCphj -ir1gE+zNP7gtzH4HOBzz3/q6GK5HmqwWth3X35ySrgrhnUZZX+plm9gRIRIqmijh -hdDp/3/2FcskQzr9UvIQDB14TbbSVAsDx5cQUM5F1nS1AAJNSrebuEcBeeM0N1HP -tqWmcJuAHtTlk+K5yk02cgbP9926vlty1uI46UyI4t/xOxmIY6gXlcSMbBnVmB0s -E+sKJTE7QrDpRRNiseCNLZcr/TNp9lrFpaUXz/JwXc+c1VC8UmARk9NLHsfoGz5H -fvhiUwl96wtvu1YKIev9nfVp1bb3/XeNAVJd+hNxOlkv68s3feutvv7vQR14E8cv -CVTXK7aAZKkWJl2n8pPohsXs5vwrsG36oFSH98jehLtzLrpgtWj6N7U8SWhI9JlT -EaIpEL/C1foVJeSZs8Tq1sqYaw81lovDFk8wuS1eFhWeEVodJQsfCPBgsQGZ46oZ -gWz3AU3KrB4ruNxjkJJxfgKu39pHDrv3o5ZufAHoIAHRdPTPlcH1Wi/1LLgLqHVC -9+i7N1ClsO1/VgtYmZwzxWxsEJOcE2+vOROoVzgMh5lGhCLh6/3VTL96hIjcMp4W -oD8ElPP+m/v6iA== -=70vD ------END PGP PUBLIC KEY BLOCK----- diff --git a/ebtables-config b/ebtables-config deleted file mode 100644 index 69d9289..0000000 --- a/ebtables-config +++ /dev/null @@ -1,11 +0,0 @@ -# Save current firewall rules on stop. -# Value: yes|no, default: no -# Saves all firewall rules if firewall gets stopped -# (e.g. on system shutdown). -EBTABLES_SAVE_ON_STOP="no" - -# Save (and restore) rule counters. -# Value: yes|no, default: no -# Save rule counters when saving a kernel table to a file. If the -# rule counters were saved, they will be restored when restoring the table. -EBTABLES_SAVE_COUNTER="no" diff --git a/ebtables-helper b/ebtables-helper deleted file mode 100644 index e63bd2b..0000000 --- a/ebtables-helper +++ /dev/null @@ -1,102 +0,0 @@ -#!/bin/bash - -# compat for removed initscripts dependency - -success() { - echo "[ OK ]" - return 0 -} - -failure() { - echo "[FAILED]" - return 1 -} - -# internal variables -EBTABLES_CONFIG=/etc/sysconfig/ebtables-config -EBTABLES_DATA=/etc/sysconfig/ebtables -EBTABLES_TABLES="broute filter nat" -VAR_SUBSYS_EBTABLES=/var/lock/subsys/ebtables - -# ebtables-config defaults -EBTABLES_SAVE_ON_STOP="no" -EBTABLES_SAVE_ON_RESTART="no" -EBTABLES_SAVE_COUNTER="no" - -# load config if existing -[ -f "$EBTABLES_CONFIG" ] && . "$EBTABLES_CONFIG" - -initialize() { - local ret=0 - for table in $EBTABLES_TABLES; do - ebtables -t $table --init-table || ret=1 - done - return $ret -} - -sanitize_dump() { - local drop=false - - export EBTABLES_TABLES - - cat $1 | while read line; do - case $line in - \**) - drop=false - local table="${line#\*}" - local found=false - for t in $EBTABLES_TABLES; do - if [[ $t == $table ]]; then - found=true - break - fi - done - $found || drop=true - ;; - esac - $drop || echo "$line" - done -} - -start() { - if [ -f $EBTABLES_DATA ]; then - echo -n $"ebtables: loading ruleset from $EBTABLES_DATA: " - sanitize_dump $EBTABLES_DATA | ebtables-restore - else - echo -n $"ebtables: no stored ruleset, initializing empty tables: " - initialize - fi - local ret=$? - touch $VAR_SUBSYS_EBTABLES - return $ret -} - -save() { - echo -n $"ebtables: saving active ruleset to $EBTABLES_DATA: " - export EBTABLES_SAVE_COUNTER - ebtables-save >$EBTABLES_DATA && success || failure -} - -case $1 in - start) - [ -f "$VAR_SUBSYS_EBTABLES" ] && exit 0 - start && success || failure - RETVAL=$? - ;; - stop) - [ "x$EBTABLES_SAVE_ON_STOP" = "xyes" ] && save - echo -n $"ebtables: stopping firewall: " - initialize && success || failure - RETVAL=$? - rm -f $VAR_SUBSYS_EBTABLES - ;; - save) - save - ;; - *) - echo "usage: ${0##*/} {start|stop|save}" >&2 - RETVAL=2 - ;; -esac - -exit $RETVAL diff --git a/ebtables.service b/ebtables.service deleted file mode 100644 index b096f1d..0000000 --- a/ebtables.service +++ /dev/null @@ -1,11 +0,0 @@ -[Unit] -Description=Ethernet Bridge Filtering tables - -[Service] -Type=oneshot -RemainAfterExit=yes -ExecStart=/usr/libexec/ebtables-helper start -ExecStop=/usr/libexec/ebtables-helper stop - -[Install] -WantedBy=multi-user.target diff --git a/iptables-1.8.11-command-options-fix.patch b/iptables-1.8.11-command-options-fix.patch deleted file mode 100644 index f6eecb1..0000000 --- a/iptables-1.8.11-command-options-fix.patch +++ /dev/null @@ -1,27 +0,0 @@ -commit 192c3a6bc18f206895ec5e38812d648ccfe7e281 -Author: Phil Sutter -Date: Wed Apr 23 12:36:13 2025 +0200 - - xshared: Accept an option if any given command allows it - - Fixed commit made option checking overly strict: Some commands may be - commbined (foremost --list and --zero), reject a given option only if it - is not allowed by any of the given commands. - - Reported-by: Adam Nielsen - Fixes: 9c09d28102bb4 ("xshared: Simplify generic_opt_check()") - Signed-off-by: Phil Sutter - -diff --git a/iptables/xshared.c b/iptables/xshared.c -index cdfd11ab..fc61e0fd 100644 ---- a/iptables/xshared.c -+++ b/iptables/xshared.c -@@ -980,7 +980,7 @@ static void generic_opt_check(struct xt_cmd_parse_ops *ops, - */ - for (i = 0, optval = 1; i < NUMBER_OF_OPT; optval = (1 << ++i)) { - if ((options & optval) && -- (options_v_commands[i] & command) != command) -+ !(options_v_commands[i] & command)) - xtables_error(PARAMETER_PROBLEM, - "Illegal option `%s' with this command", - ops->option_name(optval)); diff --git a/iptables-1.8.11-fix-interface-comparisons.patch b/iptables-1.8.11-fix-interface-comparisons.patch deleted file mode 100644 index b038616..0000000 --- a/iptables-1.8.11-fix-interface-comparisons.patch +++ /dev/null @@ -1,172 +0,0 @@ -From 40406dbfaefbc204134452b2747bae4f6a122848 Mon Sep 17 00:00:00 2001 -From: Jeremy Sowden -Date: Mon, 18 Nov 2024 13:56:50 +0000 -Subject: nft: fix interface comparisons in `-C` commands - -Commit 9ccae6397475 ("nft: Leave interface masks alone when parsing from -kernel") removed code which explicitly set interface masks to all ones. The -result of this is that they are zero. However, they are used to mask interfaces -in `is_same_interfaces`. Consequently, the masked values are alway zero, the -comparisons are always true, and check commands which ought to fail succeed: - - # iptables -N test - # iptables -A test -i lo \! -o lo -j REJECT - # iptables -v -L test - Chain test (0 references) - pkts bytes target prot opt in out source destination - 0 0 REJECT all -- lo !lo anywhere anywhere reject-with icmp-port-unreachable - # iptables -v -C test -i abcdefgh \! -o abcdefgh -j REJECT - REJECT all opt -- in lo out !lo 0.0.0.0/0 -> 0.0.0.0/0 reject-with icmp-port-unreachable - -Remove the mask parameters from `is_same_interfaces`. Add a test-case. - -Fixes: 9ccae6397475 ("nft: Leave interface masks alone when parsing from kernel") -Signed-off-by: Jeremy Sowden -Signed-off-by: Phil Sutter ---- - iptables/nft-arp.c | 10 ++---- - iptables/nft-ipv4.c | 4 +-- - iptables/nft-ipv6.c | 6 +--- - iptables/nft-shared.c | 36 +++++----------------- - iptables/nft-shared.h | 6 +--- - .../testcases/nft-only/0020-compare-interfaces_0 | 9 ++++++ - 6 files changed, 22 insertions(+), 49 deletions(-) - create mode 100755 iptables/tests/shell/testcases/nft-only/0020-compare-interfaces_0 - -diff --git a/iptables/nft-arp.c b/iptables/nft-arp.c -index 264864c3..c11d64c3 100644 ---- a/iptables/nft-arp.c -+++ b/iptables/nft-arp.c -@@ -385,14 +385,8 @@ static bool nft_arp_is_same(const struct iptables_command_state *cs_a, - return false; - } - -- return is_same_interfaces(a->arp.iniface, -- a->arp.outiface, -- (unsigned char *)a->arp.iniface_mask, -- (unsigned char *)a->arp.outiface_mask, -- b->arp.iniface, -- b->arp.outiface, -- (unsigned char *)b->arp.iniface_mask, -- (unsigned char *)b->arp.outiface_mask); -+ return is_same_interfaces(a->arp.iniface, a->arp.outiface, -+ b->arp.iniface, b->arp.outiface); - } - - static void nft_arp_save_chain(const struct nftnl_chain *c, const char *policy) -diff --git a/iptables/nft-ipv4.c b/iptables/nft-ipv4.c -index 74092875..0c8bd291 100644 ---- a/iptables/nft-ipv4.c -+++ b/iptables/nft-ipv4.c -@@ -113,9 +113,7 @@ static bool nft_ipv4_is_same(const struct iptables_command_state *a, - } - - return is_same_interfaces(a->fw.ip.iniface, a->fw.ip.outiface, -- a->fw.ip.iniface_mask, a->fw.ip.outiface_mask, -- b->fw.ip.iniface, b->fw.ip.outiface, -- b->fw.ip.iniface_mask, b->fw.ip.outiface_mask); -+ b->fw.ip.iniface, b->fw.ip.outiface); - } - - static void nft_ipv4_set_goto_flag(struct iptables_command_state *cs) -diff --git a/iptables/nft-ipv6.c b/iptables/nft-ipv6.c -index b184f8af..4dbb2af2 100644 ---- a/iptables/nft-ipv6.c -+++ b/iptables/nft-ipv6.c -@@ -99,11 +99,7 @@ static bool nft_ipv6_is_same(const struct iptables_command_state *a, - } - - return is_same_interfaces(a->fw6.ipv6.iniface, a->fw6.ipv6.outiface, -- a->fw6.ipv6.iniface_mask, -- a->fw6.ipv6.outiface_mask, -- b->fw6.ipv6.iniface, b->fw6.ipv6.outiface, -- b->fw6.ipv6.iniface_mask, -- b->fw6.ipv6.outiface_mask); -+ b->fw6.ipv6.iniface, b->fw6.ipv6.outiface); - } - - static void nft_ipv6_set_goto_flag(struct iptables_command_state *cs) -diff --git a/iptables/nft-shared.c b/iptables/nft-shared.c -index 6775578b..2c29e68f 100644 ---- a/iptables/nft-shared.c -+++ b/iptables/nft-shared.c -@@ -220,36 +220,16 @@ void add_l4proto(struct nft_handle *h, struct nftnl_rule *r, - } - - bool is_same_interfaces(const char *a_iniface, const char *a_outiface, -- unsigned const char *a_iniface_mask, -- unsigned const char *a_outiface_mask, -- const char *b_iniface, const char *b_outiface, -- unsigned const char *b_iniface_mask, -- unsigned const char *b_outiface_mask) -+ const char *b_iniface, const char *b_outiface) - { -- int i; -- -- for (i = 0; i < IFNAMSIZ; i++) { -- if (a_iniface_mask[i] != b_iniface_mask[i]) { -- DEBUGP("different iniface mask %x, %x (%d)\n", -- a_iniface_mask[i] & 0xff, b_iniface_mask[i] & 0xff, i); -- return false; -- } -- if ((a_iniface[i] & a_iniface_mask[i]) -- != (b_iniface[i] & b_iniface_mask[i])) { -- DEBUGP("different iniface\n"); -- return false; -- } -- if (a_outiface_mask[i] != b_outiface_mask[i]) { -- DEBUGP("different outiface mask\n"); -- return false; -- } -- if ((a_outiface[i] & a_outiface_mask[i]) -- != (b_outiface[i] & b_outiface_mask[i])) { -- DEBUGP("different outiface\n"); -- return false; -- } -+ if (strncmp(a_iniface, b_iniface, IFNAMSIZ)) { -+ DEBUGP("different iniface\n"); -+ return false; -+ } -+ if (strncmp(a_outiface, b_outiface, IFNAMSIZ)) { -+ DEBUGP("different outiface\n"); -+ return false; - } -- - return true; - } - -diff --git a/iptables/nft-shared.h b/iptables/nft-shared.h -index 51d1e460..b57aee1f 100644 ---- a/iptables/nft-shared.h -+++ b/iptables/nft-shared.h -@@ -105,11 +105,7 @@ void add_l4proto(struct nft_handle *h, struct nftnl_rule *r, uint8_t proto, uint - void add_compat(struct nftnl_rule *r, uint32_t proto, bool inv); - - bool is_same_interfaces(const char *a_iniface, const char *a_outiface, -- unsigned const char *a_iniface_mask, -- unsigned const char *a_outiface_mask, -- const char *b_iniface, const char *b_outiface, -- unsigned const char *b_iniface_mask, -- unsigned const char *b_outiface_mask); -+ const char *b_iniface, const char *b_outiface); - - void __get_cmp_data(struct nftnl_expr *e, void *data, size_t dlen, uint8_t *op); - void get_cmp_data(struct nftnl_expr *e, void *data, size_t dlen, bool *inv); -diff --git a/iptables/tests/shell/testcases/nft-only/0020-compare-interfaces_0 b/iptables/tests/shell/testcases/nft-only/0020-compare-interfaces_0 -new file mode 100755 -index 00000000..278cd648 ---- /dev/null -+++ b/iptables/tests/shell/testcases/nft-only/0020-compare-interfaces_0 -@@ -0,0 +1,9 @@ -+#!/bin/bash -+ -+[[ $XT_MULTI == *xtables-nft-multi ]] || { echo "skip $XT_MULTI"; exit 0; } -+ -+$XT_MULTI iptables -N test -+$XT_MULTI iptables -A test -i lo \! -o lo -j REJECT -+$XT_MULTI iptables -C test -i abcdefgh \! -o abcdefgh -j REJECT 2>/dev/null && exit 1 -+ -+exit 0 --- -cgit v1.2.3 - diff --git a/iptables.spec b/iptables.spec index c999d94..34455fc 100644 --- a/iptables.spec +++ b/iptables.spec @@ -10,35 +10,41 @@ Name: iptables Summary: Tools for managing Linux kernel packet filtering capabilities URL: https://www.netfilter.org/projects/iptables -Version: 1.8.11 -Release: 12%{?dist} -Source0: %{url}/files/%{name}-%{version}.tar.xz -source1: %{url}/files/%{name}-%{version}.tar.xz.sig -Source2: coreteam-gpg-key-0xD70D1A666ACF2B21.txt -Source3: iptables.init -Source4: iptables-config -Source5: iptables.service -Source6: sysconfig_iptables -Source7: sysconfig_ip6tables -Source8: arptables-helper -Source9: arptables.service -Source10: ebtables.service -Source11: ebtables-helper -Source12: ebtables-config -# Patch to fix -C handling, already upstream -# https://git.netfilter.org/iptables/patch/?id=40406dbfaefbc204134452b2747bae4f6a122848 -Patch1: iptables-1.8.11-fix-interface-comparisons.patch -# Patch to fix overly strict command option checking -# https://git.netfilter.org/iptables/patch/?id=192c3a6bc18f206895ec5e38812d648ccfe7e281 -Patch2: iptables-1.8.11-command-options-fix.patch +Version: 1.8.9 +Release: 5%{?dist} +Source: %{url}/files/%{name}-%{version}.tar.xz +Source1: iptables.init +Source2: iptables-config +Source3: iptables.service +Source4: sysconfig_iptables +Source5: sysconfig_ip6tables +Source6: arptables-nft-helper + +Patch001: 0001-extensions-NAT-Fix-for-Werror-format-security.patch +Patch002: 0002-etc-Drop-xtables.conf.patch +Patch003: 0003-Proper-fix-for-unknown-argument-error-message.patch +Patch004: 0004-ebtables-Refuse-unselected-targets-options.patch +Patch005: 0005-tests-xlate-Properly-split-input-in-replay-mode.patch +Patch006: 0006-extensions-libebt_redirect-Fix-target-translation.patch +Patch007: 0007-extensions-libebt_redirect-Fix-for-wrong-syntax-in-t.patch +Patch008: 0008-extensions-libebt_ip-Do-not-use-ip-dscp-for-translat.patch +Patch009: 0009-extensions-libebt_ip-Translation-has-to-match-on-eth.patch +Patch010: 0010-xt_sctp-add-the-missing-chunk-types-in-sctp_help.patch +Patch011: 0011-include-Add-missing-linux-netfilter-xt_LOG.h.patch +Patch012: 0012-nft-restore-Fix-for-deletion-of-new-referenced-rule.patch +Patch013: 0013-ip6tables-Fix-checking-existence-of-rule.patch +Patch014: 0014-nft-shared-Drop-unused-include.patch +Patch015: 0015-arptables-Fix-parsing-of-inverted-arp-operation-matc.patch +Patch016: 0016-arptables-Don-t-omit-standard-matches-if-inverted.patch +Patch017: 0017-xshared-Fix-parsing-of-option-arguments-in-same-word.patch # pf.os: ISC license # iptables-apply: Artistic Licence 2.0 -License: GPL-2.0-only AND Artistic-2.0 AND ISC +License: GPLv2 and Artistic Licence 2.0 and ISC # libnetfilter_conntrack is needed for xt_connlabel BuildRequires: pkgconfig(libnetfilter_conntrack) -# libnfnetlink-devel is required for nfnl_osf +# libnfnetlink-devel is requires for nfnl_osf BuildRequires: pkgconfig(libnfnetlink) BuildRequires: libselinux-devel BuildRequires: kernel-headers @@ -48,35 +54,40 @@ BuildRequires: bison BuildRequires: flex BuildRequires: gcc BuildRequires: pkgconfig(libmnl) >= 1.0 -BuildRequires: pkgconfig(libnftnl) >= 1.2.6 +BuildRequires: pkgconfig(libnftnl) >= 1.1.6 # libpcap-devel for nfbpf_compile BuildRequires: libpcap-devel BuildRequires: autoconf BuildRequires: automake BuildRequires: libtool BuildRequires: make -BuildRequires: gnupg2 %description The iptables utility controls the network packet filtering code in the Linux kernel. If you need to set up firewalls and/or IP masquerading, you should install this package. +%package compat +Summary: Temporary transitioning package +Obsoletes: %{name} < 1.8.7-4 +Requires: %{name}-legacy = %{version}-%{release} +Requires: %{name}-utils = %{version}-%{release} + +%description compat +This package only exists to help transition iptables users to the new +package split. It will be removed after one distribution release cycle, please +do not reference it or depend on it in any way. + %package legacy Summary: Legacy tools for managing Linux kernel packet filtering capabilities Requires: %{name}-legacy-libs%{?_isa} = %{version}-%{release} Requires: %{name}-libs%{?_isa} = %{version}-%{release} Conflicts: setup < 2.10.4-1 -Conflicts: alternatives < 1.32-1 -Requires(post): /usr/sbin/update-alternatives -Requires(postun): /usr/sbin/update-alternatives +Requires(post): %{_sbindir}/update-alternatives +Requires(postun): %{_sbindir}/update-alternatives %if 0%{?rhel} < 9 Provides: iptables %endif -Provides: %{name}-compat = %{version}-%{release} -Obsoletes: %{name}-compat < 1.8.9-7 - -%sbin_merge_compat %{_prefix}/sbin/iptables %description legacy The iptables utility controls the network packet filtering code in the @@ -100,8 +111,9 @@ Summary: iptables legacy libraries %description legacy-libs iptables libraries. -Please remember that libip*tc libraries do neither have a stable API nor a real -so version. For more information about this, please have a look at +Please remember that libip*tc libraries do neither have a stable API nor a real so version. + +For more information about this, please have a look at http://www.netfilter.org/documentation/FAQ/netfilter-faq-4.html#ss4.5 @@ -135,14 +147,6 @@ Requires: %{name}-utils = %{version}-%{release} Obsoletes: %{name} < 1.4.16.1 # obsolete ipv6 sub package Obsoletes: %{name}-ipv6 < 1.4.11.1 -# Look at me, I'm the new arptables-services now! -Conflicts: %{name}-nft < 1.8.11-5 -Obsoletes: arptables-services < 0.0.5-16 -Provides: arptables-services = %{version}-%{release} -# Look at me, I'm the new ebtables-services now! -# (With epoch to turn our version number higher value) -Obsoletes: ebtables-services < 2.0.11-20 -Provides: ebtables-services = 1:%{version}-%{release} BuildArch: noarch %description services @@ -165,25 +169,19 @@ a safer way to update iptables remotely. %package nft Summary: nftables compatibility for iptables, arptables and ebtables Requires: %{name}-libs%{?_isa} = %{version}-%{release} -Requires(post): /usr/sbin/update-alternatives -Requires(post): /usr/bin/readlink -Requires(postun): /usr/sbin/update-alternatives +Requires(post): %{_sbindir}/update-alternatives +Requires(post): %{_bindir}/readlink +Requires(postun): %{_sbindir}/update-alternatives Obsoletes: iptables-compat < 1.6.2-4 Provides: arptables-helper Provides: iptables Provides: arptables Provides: ebtables -# allowing old arptables-legacy will break when switching alternatives -# due to the dropped arptables-helper symlink -Conflicts: arptables-legacy < 0.0.5-16 - -%sbin_merge_compat %{_prefix}/sbin/iptables %description nft nftables compatibility for iptables, arptables and ebtables. %prep -%{gpgverify} --keyring='%{SOURCE2}' --signature='%{SOURCE1}' --data='%{SOURCE0}' %autosetup -p1 %build @@ -206,24 +204,20 @@ rm -f %{buildroot}%{_libdir}/*.la # install init scripts and configuration files install -d -m 755 %{buildroot}%{script_path} -install -c -m 755 %{SOURCE3} %{buildroot}%{script_path}/iptables.init -sed -e 's;iptables;ip6tables;g' -e 's;IPTABLES;IP6TABLES;g' < %{SOURCE3} > ip6tables.init +install -c -m 755 %{SOURCE1} %{buildroot}%{script_path}/iptables.init +sed -e 's;iptables;ip6tables;g' -e 's;IPTABLES;IP6TABLES;g' < %{SOURCE1} > ip6tables.init install -c -m 755 ip6tables.init %{buildroot}%{script_path}/ip6tables.init -install -p -m 755 %{SOURCE8} %{SOURCE11} %{buildroot}%{_libexecdir}/ install -d -m 755 %{buildroot}%{_sysconfdir}/sysconfig -install -c -m 600 %{SOURCE4} %{buildroot}%{_sysconfdir}/sysconfig/iptables-config -sed -e 's;iptables;ip6tables;g' -e 's;IPTABLES;IP6TABLES;g' < %{SOURCE4} > ip6tables-config +install -c -m 600 %{SOURCE2} %{buildroot}%{_sysconfdir}/sysconfig/iptables-config +sed -e 's;iptables;ip6tables;g' -e 's;IPTABLES;IP6TABLES;g' < %{SOURCE2} > ip6tables-config install -c -m 600 ip6tables-config %{buildroot}%{_sysconfdir}/sysconfig/ip6tables-config -install -c -m 600 %{SOURCE6} %{buildroot}%{_sysconfdir}/sysconfig/iptables -install -c -m 600 %{SOURCE7} %{buildroot}%{_sysconfdir}/sysconfig/ip6tables -echo '# Configure prior to use' > %{buildroot}%{_sysconfdir}/sysconfig/arptables -install -c -m 600 %{SOURCE12} %{buildroot}%{_sysconfdir}/sysconfig/ -touch %{buildroot}%{_sysconfdir}/sysconfig/ebtables +install -c -m 600 %{SOURCE4} %{buildroot}%{_sysconfdir}/sysconfig/iptables +install -c -m 600 %{SOURCE5} %{buildroot}%{_sysconfdir}/sysconfig/ip6tables # install systemd service files install -d -m 755 %{buildroot}/%{_unitdir} -install -c -m 644 %{SOURCE5} %{SOURCE9} %{SOURCE10} %{buildroot}/%{_unitdir} -sed -e 's;iptables;ip6tables;g' -e 's;IPv4;IPv6;g' -e 's;/usr/libexec/ip6tables;/usr/libexec/iptables;g' < %{SOURCE5} > ip6tables.service +install -c -m 644 %{SOURCE3} %{buildroot}/%{_unitdir} +sed -e 's;iptables;ip6tables;g' -e 's;IPv4;IPv6;g' -e 's;/usr/libexec/ip6tables;/usr/libexec/iptables;g' < %{SOURCE3} > ip6tables.service install -c -m 644 ip6tables.service %{buildroot}/%{_unitdir} # install legacy actions for service command @@ -249,42 +243,38 @@ install -c -m 755 ip6tabes.panic-legacy %{buildroot}/%{legacy_actions}/ip6tables # Remove /etc/ethertypes (now part of setup) rm -f %{buildroot}%{_sysconfdir}/ethertypes +install -p -D -m 755 %{SOURCE6} %{buildroot}%{_libexecdir}/ +touch %{buildroot}%{_libexecdir}/arptables-helper + # prepare for alternatives touch %{buildroot}%{_mandir}/man8/arptables.8 touch %{buildroot}%{_mandir}/man8/arptables-save.8 touch %{buildroot}%{_mandir}/man8/arptables-restore.8 touch %{buildroot}%{_mandir}/man8/ebtables.8 -rm %{buildroot}%{_sbindir}/{ip,ip6,arp,eb}tables{,-save,-restore} -touch %{buildroot}%{_sbindir}/{ip,ip6,arp,eb}tables{,-save,-restore} + +# Drop xtables.conf, it's not used +rm -f %{buildroot}%{_sysconfdir}/xtables.conf # fix absolute symlink -ln -sf --relative %{buildroot}%{_sbindir}/xtables-legacy-multi %{buildroot}%{_bindir}/iptables-xml +rm -f %{buildroot}%{_bindir}/iptables-xml +ln -s ../sbin/xtables-legacy-multi %{buildroot}%{_bindir}/iptables-xml %ldconfig_scriptlets %post legacy pfx=%{_sbindir}/iptables pfx6=%{_sbindir}/ip6tables -update-alternatives --install \ +%{_sbindir}/update-alternatives --install \ $pfx iptables $pfx-legacy 10 \ - --follower $pfx6 ip6tables $pfx6-legacy \ - --follower $pfx-restore iptables-restore $pfx-legacy-restore \ - --follower $pfx-save iptables-save $pfx-legacy-save \ - --follower $pfx6-restore ip6tables-restore $pfx6-legacy-restore \ - --follower $pfx6-save ip6tables-save $pfx6-legacy-save - -%if "%{_sbindir}" == "%{_bindir}" -# Make sure that symlinks in /usr/sbin/ are not missing, if /usr/sbin is a -# directory. Those symlinks will only be created if there is no symlink -# or file already. -for name in ip{,6}tables{,-save,-restore}; do - test -h /usr/sbin || ln -s ../bin/$name /usr/sbin/$name 2>/dev/null || : -done -%endif + --slave $pfx6 ip6tables $pfx6-legacy \ + --slave $pfx-restore iptables-restore $pfx-legacy-restore \ + --slave $pfx-save iptables-save $pfx-legacy-save \ + --slave $pfx6-restore ip6tables-restore $pfx6-legacy-restore \ + --slave $pfx6-save ip6tables-save $pfx6-legacy-save %postun legacy if [ $1 -eq 0 ]; then - update-alternatives --remove \ + %{_sbindir}/update-alternatives --remove \ iptables %{_sbindir}/iptables-legacy fi @@ -300,112 +290,97 @@ cp /var/lib/alternatives/iptables /var/tmp/alternatives.iptables.setup %triggerpostun legacy -- iptables > 1.8.0 pfx=%{_sbindir}/iptables pfx6=%{_sbindir}/ip6tables -update-alternatives --install \ +%{_sbindir}/update-alternatives --install \ $pfx iptables $pfx-legacy 10 \ - --follower $pfx6 ip6tables $pfx6-legacy \ - --follower $pfx-restore iptables-restore $pfx-legacy-restore \ - --follower $pfx-save iptables-save $pfx-legacy-save \ - --follower $pfx6-restore ip6tables-restore $pfx6-legacy-restore \ - --follower $pfx6-save ip6tables-save $pfx6-legacy-save + --slave $pfx6 ip6tables $pfx6-legacy \ + --slave $pfx-restore iptables-restore $pfx-legacy-restore \ + --slave $pfx-save iptables-save $pfx-legacy-save \ + --slave $pfx6-restore ip6tables-restore $pfx6-legacy-restore \ + --slave $pfx6-save ip6tables-save $pfx6-legacy-save alternatives --set iptables $(/dev/null || : -done -%endif - %post services -%systemd_post arptables.service ebtables.service %systemd_post iptables.service ip6tables.service %preun services -%systemd_preun arptables.service ebtables.service %systemd_preun iptables.service ip6tables.service %postun services %?ldconfig -%systemd_postun arptables.service ebtables.service %systemd_postun iptables.service ip6tables.service %post -e nft [[ %%{_excludedocs} == 1 ]] || do_man=true -# remove non-symlinks in spots managed by alternatives -# to cover for updates from not-yet-alternatived versions -for pfx in %{_prefix}/sbin/{eb,arp}tables; do - for sfx in "" "-restore" "-save"; do - if [ "$(readlink -e $pfx$sfx)" == $pfx$sfx ]; then - rm -f $pfx$sfx - fi - done -done -for manpfx in %{_mandir}/man8/{eb,arp}tables; do - for sfx in {,-restore,-save}.8.gz; do - if [ "$(readlink -e $manpfx$sfx)" == $manpfx$sfx ]; then - rm -f $manpfx$sfx - fi - done -done - pfx=%{_sbindir}/iptables pfx6=%{_sbindir}/ip6tables -update-alternatives --install \ +%{_sbindir}/update-alternatives --install \ $pfx iptables $pfx-nft 10 \ - --follower $pfx6 ip6tables $pfx6-nft \ - --follower $pfx-restore iptables-restore $pfx-nft-restore \ - --follower $pfx-save iptables-save $pfx-nft-save \ - --follower $pfx6-restore ip6tables-restore $pfx6-nft-restore \ - --follower $pfx6-save ip6tables-save $pfx6-nft-save + --slave $pfx6 ip6tables $pfx6-nft \ + --slave $pfx-restore iptables-restore $pfx-nft-restore \ + --slave $pfx-save iptables-save $pfx-nft-save \ + --slave $pfx6-restore ip6tables-restore $pfx6-nft-restore \ + --slave $pfx6-save ip6tables-save $pfx6-nft-save pfx=%{_sbindir}/ebtables manpfx=%{_mandir}/man8/ebtables -update-alternatives --install \ +for sfx in "" "-restore" "-save"; do + if [ "$(readlink -e $pfx$sfx)" == $pfx$sfx ]; then + rm -f $pfx$sfx + fi +done +if [ "$(readlink -e $manpfx.8.gz)" == $manpfx.8.gz ]; then + rm -f $manpfx.8.gz +fi +%{_sbindir}/update-alternatives --install \ $pfx ebtables $pfx-nft 10 \ - --follower $pfx-save ebtables-save $pfx-nft-save \ - --follower $pfx-restore ebtables-restore $pfx-nft-restore \ - ${do_man:+--follower $manpfx.8.gz ebtables-man $manpfx-nft.8.gz} + --slave $pfx-save ebtables-save $pfx-nft-save \ + --slave $pfx-restore ebtables-restore $pfx-nft-restore \ + ${do_man:+--slave $manpfx.8.gz ebtables-man $manpfx-nft.8.gz} pfx=%{_sbindir}/arptables manpfx=%{_mandir}/man8/arptables -update-alternatives --install \ - $pfx arptables $pfx-nft 10 \ - --follower $pfx-save arptables-save $pfx-nft-save \ - --follower $pfx-restore arptables-restore $pfx-nft-restore \ - ${do_man:+--follower $manpfx.8.gz arptables-man $manpfx-nft.8.gz} \ - ${do_man:+--follower $manpfx-save.8.gz arptables-save-man $manpfx-nft-save.8.gz} \ - ${do_man:+--follower $manpfx-restore.8.gz arptables-restore-man $manpfx-nft-restore.8.gz} - -%if "%{_sbindir}" == "%{_bindir}" -# Make sure that symlinks in /usr/sbin/ are not missing, if /usr/sbin is a -# directory. Those symlinks will only be created if there is no symlink -# or file already. -for name in ip{,6}tables{,-save,-restore} ebtables{,-save,-restore} arptables{,-save,-restore}; do - test -h /usr/sbin || ln -s ../bin/$name /usr/sbin/$name 2>/dev/null || : +lepfx=%{_libexecdir}/arptables +for sfx in "" "-restore" "-save"; do + if [ "$(readlink -e $pfx$sfx)" == $pfx$sfx ]; then + rm -f $pfx$sfx + fi + if [ "$(readlink -e $manpfx$sfx.8.gz)" == $manpfx$sfx.8.gz ]; then + rm -f $manpfx$sfx.8.gz + fi done -%endif +if [ "$(readlink -e $lepfx-helper)" == $lepfx-helper ]; then + rm -f $lepfx-helper +fi +%{_sbindir}/update-alternatives --install \ + $pfx arptables $pfx-nft 10 \ + --slave $pfx-save arptables-save $pfx-nft-save \ + --slave $pfx-restore arptables-restore $pfx-nft-restore \ + ${do_man:+--slave $manpfx.8.gz arptables-man $manpfx-nft.8.gz} \ + ${do_man:+--slave $manpfx-save.8.gz arptables-save-man $manpfx-nft-save.8.gz} \ + ${do_man:+--slave $manpfx-restore.8.gz arptables-restore-man $manpfx-nft-restore.8.gz} \ + --slave $lepfx-helper arptables-helper $lepfx-nft-helper %postun nft if [ $1 -eq 0 ]; then for cmd in iptables ebtables arptables; do - update-alternatives --remove $cmd %{_sbindir}/$cmd-nft + %{_sbindir}/update-alternatives --remove \ + $cmd %{_sbindir}/$cmd-nft done fi +%files compat + %files legacy %{_sbindir}/ip{,6}tables-legacy* %{_sbindir}/xtables-legacy-multi %{_bindir}/iptables-xml %{_mandir}/man1/iptables-xml* %{_mandir}/man8/xtables-legacy* -%dir %{_datadir}/xtables %{_datadir}/xtables/iptables.xslt -%ghost %attr(0755,root,root) %{_sbindir}/ip{,6}tables{,-save,-restore} +%ghost %{_sbindir}/ip{,6}tables{,-save,-restore} %files libs %license COPYING @@ -434,13 +409,9 @@ fi %dir %{script_path} %{script_path}/ip{,6}tables.init %config(noreplace) %{_sysconfdir}/sysconfig/ip{,6}tables{,-config} -%config(noreplace) %{_sysconfdir}/sysconfig/arptables -%config(noreplace) %{_sysconfdir}/sysconfig/ebtables-config -%ghost %{_sysconfdir}/sysconfig/ebtables -%{_unitdir}/{arp,eb,ip,ip6}tables.service +%{_unitdir}/ip{,6}tables.service %dir %{legacy_actions}/ip{,6}tables %{legacy_actions}/ip{,6}tables/{save,panic} -%{_libexecdir}/{arp,eb}tables-helper %files utils %license COPYING @@ -460,109 +431,22 @@ fi %{_sbindir}/xtables-nft-multi %{_sbindir}/xtables-monitor %{_sbindir}/ebtables-translate -%{_sbindir}/arptables-translate %dir %{_libdir}/xtables %{_libdir}/xtables/lib{arp,eb}t* +%{_libexecdir}/arptables-nft-helper %{_mandir}/man8/xtables-monitor* %{_mandir}/man8/xtables-translate* %{_mandir}/man8/*-nft* %{_mandir}/man8/ip{,6}tables{,-restore}-translate* %{_mandir}/man8/ebtables-translate* -%{_mandir}/man8/arptables-translate* -%ghost %attr(0755,root,root) %{_sbindir}/ip{,6}tables{,-save,-restore} -%ghost %attr(0755,root,root) %{_sbindir}/{eb,arp}tables{,-save,-restore} +%ghost %{_sbindir}/ip{,6}tables{,-save,-restore} +%ghost %{_sbindir}/{eb,arp}tables{,-save,-restore} +%ghost %{_libexecdir}/arptables-helper %ghost %{_mandir}/man8/arptables{,-save,-restore}.8.gz %ghost %{_mandir}/man8/ebtables.8.gz %changelog -* Tue Oct 28 2025 Paul Wouters - 1.8.11-12 -- Pull in upstream fix for too strict command option parsing - -* Thu Jul 24 2025 Fedora Release Engineering - 1.8.11-11 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild - -* Tue May 20 2025 Phil Sutter - 1.8.11-10 -- Fix for ghost files not present in iptables-nft RPM - -* Wed May 07 2025 Zbigniew Jedrzejewski-Szmek - 1.8.11-9 -- Reapply the change to keep symlinks managed by alternatives under /usr/bin, - this time with a scriptlet create symlinks if /usr/sbin is unmerged. - -* Sat May 03 2025 Phil Sutter - 1.8.11-8 -- Revert last release, it breaks alternatives symlinks - -* Fri Apr 25 2025 Zbigniew Jedrzejewski-Szmek - 1.8.11-7 -- Keep symlinks managed by alternatives under /usr/bin - -* Sun Apr 20 2025 Kevin Fenzi - 1.8.11-6 -- Add patch to fix -C handling ( fixes rhbz#2360423 ) - -* Thu Apr 03 2025 Phil Sutter - 1.8.11-5 -- iptables-services to assimilate arptables- and ebtables-services - -* Fri Jan 17 2025 Fedora Release Engineering -- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild - -* Tue Jan 14 2025 Zbigniew Jedrzejewski-Szmek - 1.8.11-3 -- Keep symlinks managed by alternatives under /usr/sbin - -* Sun Jan 12 2025 Zbigniew Jędrzejewski-Szmek - 1.8.11-2 -- Rebuilt for the bin-sbin merge (2nd attempt) - -* Fri Nov 08 2024 Phil Sutter - 1.8.11-1 -- new version - -* Thu Jul 18 2024 Fedora Release Engineering - 1.8.10-15 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild - -* Sat Jul 13 2024 Zbigniew Jędrzejewski-Szmek - 1.8.10-14 -- Add unmerged-sbin compat also for -legacy subpackage - -* Fri Jul 12 2024 Zbigniew Jędrzejewski-Szmek - 1.8.10-13 -- Bump release and add changelog entry - -* Tue Jul 09 2024 Zbigniew Jędrzejewski-Szmek - 1.8.10-12 -- Rebuilt for the bin-sbin merge - -* Fri Jul 05 2024 Phil Sutter - 1.8.10-11 -- Add missing build dependency - -* Fri Jul 05 2024 Phil Sutter - 1.8.10-10 -- Verify tarball GPG signature - -* Wed Jul 03 2024 Phil Sutter - 1.8.10-9 -- Backport fixes from upstream - -* Tue May 21 2024 Phil Sutter - 1.8.10-8 -- Make iptables-legacy own %%{_datadir}/xtables - -* Wed Jan 24 2024 Fedora Release Engineering - 1.8.10-7 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild - -* Sat Jan 20 2024 Fedora Release Engineering - 1.8.10-6 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild - -* Thu Jan 11 2024 Phil Sutter - 1.8.10-5 -- Backport fixes from upstream -- Fix flatpak build - -* Tue Nov 07 2023 Phil Sutter - 1.8.10-4 -- The actual obsoletes fix - -* Tue Nov 07 2023 Phil Sutter - 1.8.10-3 -- Fix compat sub-package obsoletion - -* Tue Oct 10 2023 Phil Sutter - 1.8.10-2 -- Obsolete dropped compat package - -* Tue Oct 10 2023 Phil Sutter - 1.8.10-1 -- New version 1.8.10 -- Drop compat sub-package - -* Tue Aug 15 2023 Phil Sutter - 1.8.9-6 -- Convert license to SPDX format - * Thu Jul 20 2023 Fedora Release Engineering - 1.8.9-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild diff --git a/sources b/sources index 1f7b750..fef1030 100644 --- a/sources +++ b/sources @@ -1,2 +1 @@ -SHA512 (iptables-1.8.11.tar.xz) = 4937020bf52d57a45b76e1eba125214a2f4531de52ff1d15185faeef8bea0cd90eb77f99f81baa573944aa122f350a7198cef41d70594e1b65514784addbcc40 -SHA512 (iptables-1.8.11.tar.xz.sig) = 8bde9436b6c6c9d97d9b1cadc417035c209e39b49111ea08fe35b714bbf94721ad0b8b2870791d3bf98154f64912109c6bdeb0ee33f954d0d3a8c3582a97f3f2 +SHA512 (iptables-1.8.9.tar.xz) = e367bf286135e39b7401e852de25c1ed06d44befdffd92ed1566eb2ae9704b48ac9196cb971f43c6c83c6ad4d910443d32064bcdf618cfcef6bcab113e31ff70 diff --git a/tests/RFE-Enable-the-missing-IPv6-SET-target/runtest.sh b/tests/RFE-Enable-the-missing-IPv6-SET-target/runtest.sh index 952cd4c..32eab99 100755 --- a/tests/RFE-Enable-the-missing-IPv6-SET-target/runtest.sh +++ b/tests/RFE-Enable-the-missing-IPv6-SET-target/runtest.sh @@ -29,10 +29,12 @@ . /usr/bin/rhts-environment.sh || exit 1 . /usr/share/beakerlib/beakerlib.sh || exit 1 +PACKAGE="iptables" IPSET=testset6 rlJournalStart rlPhaseStartSetup + rlAssertRpm $PACKAGE # rlAssertRpm kernel rlRun "TmpDir=\$(mktemp -d)" 0 "Creating tmp directory" rlRun "pushd $TmpDir" diff --git a/tests/RFE-iptables-add-C-option-to-iptables-in-RHEL6/runtest.sh b/tests/RFE-iptables-add-C-option-to-iptables-in-RHEL6/runtest.sh index 26a667e..438468d 100755 --- a/tests/RFE-iptables-add-C-option-to-iptables-in-RHEL6/runtest.sh +++ b/tests/RFE-iptables-add-C-option-to-iptables-in-RHEL6/runtest.sh @@ -29,10 +29,12 @@ . /usr/bin/rhts-environment.sh || exit 1 . /usr/share/beakerlib/beakerlib.sh || exit 1 +PACKAGE="iptables" TESTD=$PWD rlJournalStart rlPhaseStartSetup + rlAssertRpm $PACKAGE rlRun "TmpDir=\$(mktemp -d)" 0 "Creating tmp directory" rlRun "pushd $TmpDir" rlRun "source $TESTD/rules.in" 0 "read ruleset" diff --git a/tests/TRACE-target-of-iptables-can-t-work-in/runtest.sh b/tests/TRACE-target-of-iptables-can-t-work-in/runtest.sh index 86652af..889c1b6 100755 --- a/tests/TRACE-target-of-iptables-can-t-work-in/runtest.sh +++ b/tests/TRACE-target-of-iptables-can-t-work-in/runtest.sh @@ -29,6 +29,7 @@ . /usr/bin/rhts-environment.sh || exit 1 . /usr/share/beakerlib/beakerlib.sh || exit 1 +PACKAGE="iptables" SERVICES="iptables ip6tables firewalld" prepare_page() { @@ -41,6 +42,7 @@ prepare_page() { rlJournalStart rlPhaseStartSetup + rlAssertRpm $PACKAGE # rlAssertRpm kernel rlLogInfo $(uname -r) rlRun "TmpDir=\$(mktemp -d)" 0 "Creating tmp directory" @@ -119,14 +121,10 @@ rlJournalStart rlRun "ip -6 route restore < ip-route.save6" 0 "restore routing info ipv6" rlRun "iptables -t raw -F" rlRun "ip6tables -t raw -F" - if rlTestVersion "$(uname -r)" "<" "4.6"; then - rlRun "rmmod nf_log_ipv4" - rlRun "rmmod nf_log_ipv6" - rlRun "rmmod nf_log_common" - rlRun "rmmod nfnetlink_log" 0,1 - else - rlLogInfo "new kernel detected: skipping unloading modules" - fi + rlRun "rmmod nf_log_ipv4" + rlRun "rmmod nf_log_ipv6" + rlRun "rmmod nf_log_common" + rlRun "rmmod nfnetlink_log" 0,1 rlLogInfo "restoring services" for svc in $SERVICES; do rlServiceRestore $svc diff --git a/tests/backport-iptables-add-libxt-cgroup-frontend/runtest.sh b/tests/backport-iptables-add-libxt-cgroup-frontend/runtest.sh index 0b4032e..888dfbd 100755 --- a/tests/backport-iptables-add-libxt-cgroup-frontend/runtest.sh +++ b/tests/backport-iptables-add-libxt-cgroup-frontend/runtest.sh @@ -29,6 +29,7 @@ . /usr/bin/rhts-environment.sh || exit 1 . /usr/share/beakerlib/beakerlib.sh || exit 1 +PACKAGE="iptables" CGNUM="15" CGNAME="15" CGDIR="/sys/fs/cgroup/net_cls/$CGNAME" @@ -40,6 +41,7 @@ SKIP6=false rlJournalStart rlPhaseStartSetup + rlAssertRpm $PACKAGE # rlAssertRpm kernel-$(uname -r) rlRun "TmpDir=\$(mktemp -d)" 0 "Creating tmp directory" rlRun "pushd $TmpDir" diff --git a/tests/initscript-sanity/runtest.sh b/tests/initscript-sanity/runtest.sh index b132033..e270b78 100755 --- a/tests/initscript-sanity/runtest.sh +++ b/tests/initscript-sanity/runtest.sh @@ -29,8 +29,11 @@ . /usr/bin/rhts-environment.sh || exit 1 . /usr/share/beakerlib/beakerlib.sh || exit 1 +PACKAGE="iptables" + rlJournalStart rlPhaseStartSetup + rlAssertRpm $PACKAGE rlRun "TmpDir=\$(mktemp -d)" 0 "Creating tmp directory" rlRun "pushd $TmpDir" rlPhaseEnd diff --git a/tests/ip6tables-do-not-accept-dst-or-src-direction-on-ip6sets/runtest.sh b/tests/ip6tables-do-not-accept-dst-or-src-direction-on-ip6sets/runtest.sh index f68925c..004d568 100755 --- a/tests/ip6tables-do-not-accept-dst-or-src-direction-on-ip6sets/runtest.sh +++ b/tests/ip6tables-do-not-accept-dst-or-src-direction-on-ip6sets/runtest.sh @@ -29,8 +29,11 @@ . /usr/bin/rhts-environment.sh || exit 1 . /usr/share/beakerlib/beakerlib.sh || exit 1 +PACKAGE="iptables" + rlJournalStart rlPhaseStartSetup + rlAssertRpm $PACKAGE rlRun "TmpDir=\$(mktemp -d)" 0 "Creating tmp directory" rlRun "pushd $TmpDir" rlRun "ip6tables-save > ip6tables.backup" diff --git a/tests/ip6tables-service-does-not-allow-dhcpv6-client-by/runtest.sh b/tests/ip6tables-service-does-not-allow-dhcpv6-client-by/runtest.sh index d06fc4a..f59a908 100755 --- a/tests/ip6tables-service-does-not-allow-dhcpv6-client-by/runtest.sh +++ b/tests/ip6tables-service-does-not-allow-dhcpv6-client-by/runtest.sh @@ -29,8 +29,11 @@ . /usr/bin/rhts-environment.sh || exit 1 . /usr/share/beakerlib/beakerlib.sh || exit 1 +PACKAGE="iptables" + rlJournalStart rlPhaseStartSetup + rlAssertRpm $PACKAGE rlRun "TmpDir=\$(mktemp -d)" 0 "Creating tmp directory" rlRun "pushd $TmpDir" rlRun "cp /etc/sysconfig/ip6tables ." diff --git a/tests/ip6tables-t-nat-A-POSTROUTING-OUTPUT-with-DROP/runtest.sh b/tests/ip6tables-t-nat-A-POSTROUTING-OUTPUT-with-DROP/runtest.sh index 2daddb3..79b2696 100755 --- a/tests/ip6tables-t-nat-A-POSTROUTING-OUTPUT-with-DROP/runtest.sh +++ b/tests/ip6tables-t-nat-A-POSTROUTING-OUTPUT-with-DROP/runtest.sh @@ -29,10 +29,12 @@ . /usr/bin/rhts-environment.sh || exit 1 . /usr/share/beakerlib/beakerlib.sh || exit 1 +PACKAGE="iptables" SERVICES="iptables ip6tables firewalld" rlJournalStart rlPhaseStartSetup + rlAssertRpm $PACKAGE rlRun "TmpDir=\$(mktemp -d)" 0 "Creating tmp directory" rlRun "pushd $TmpDir" for svc in $SERVICES; do diff --git a/tests/iptables-rule-deletion-fails-for-rules-that-use/runtest.sh b/tests/iptables-rule-deletion-fails-for-rules-that-use/runtest.sh index f409501..d17e693 100755 --- a/tests/iptables-rule-deletion-fails-for-rules-that-use/runtest.sh +++ b/tests/iptables-rule-deletion-fails-for-rules-that-use/runtest.sh @@ -29,11 +29,13 @@ . /usr/bin/rhts-environment.sh || exit 1 . /usr/share/beakerlib/beakerlib.sh || exit 1 +PACKAGE="iptables" IPSET4="ipsetv4" IPSET6="ipsetv6" rlJournalStart rlPhaseStartSetup + rlAssertRpm $PACKAGE rlRun "TmpDir=\$(mktemp -d)" 0 "Creating tmp directory" rlRun "pushd $TmpDir" rlRun "ipset create $IPSET4 hash:ip" diff --git a/tests/iptables-save-cuts-space-before-j/runtest.sh b/tests/iptables-save-cuts-space-before-j/runtest.sh index bba6bf2..a6a5099 100755 --- a/tests/iptables-save-cuts-space-before-j/runtest.sh +++ b/tests/iptables-save-cuts-space-before-j/runtest.sh @@ -29,8 +29,11 @@ . /usr/bin/rhts-environment.sh || exit 1 . /usr/share/beakerlib/beakerlib.sh || exit 1 +PACKAGE="iptables" + rlJournalStart rlPhaseStartSetup + rlAssertRpm $PACKAGE rlRun "TmpDir=\$(mktemp -d)" 0 "Creating tmp directory" rlRun "pushd $TmpDir" rlServiceStart iptables diff --git a/tests/iptables-save-modprobe-option/runtest.sh b/tests/iptables-save-modprobe-option/runtest.sh index 240c76e..22951c4 100755 --- a/tests/iptables-save-modprobe-option/runtest.sh +++ b/tests/iptables-save-modprobe-option/runtest.sh @@ -30,8 +30,11 @@ . /usr/bin/rhts-environment.sh || exit 1 . /usr/share/beakerlib/beakerlib.sh || exit 1 +PACKAGE="iptables" + rlJournalStart rlPhaseStartTest + rlAssertRpm $PACKAGE rlRun "iptables-save -M /dev/null" 0 "iptables-save -M ... supported" rlRun "iptables-save --modprobe /dev/null" 0 "iptables-save --modprobe ... supported" rlPhaseEnd diff --git a/tests/xtables-tools-locking-vulnerable-to-local-DoS/runtest.sh b/tests/xtables-tools-locking-vulnerable-to-local-DoS/runtest.sh index abfb03a..c3223b5 100755 --- a/tests/xtables-tools-locking-vulnerable-to-local-DoS/runtest.sh +++ b/tests/xtables-tools-locking-vulnerable-to-local-DoS/runtest.sh @@ -29,8 +29,11 @@ . /usr/bin/rhts-environment.sh || exit 1 . /usr/share/beakerlib/beakerlib.sh || exit 1 +PACKAGE="iptables" + rlJournalStart rlPhaseStartSetup + rlAssertRpm $PACKAGE rlRun "TmpDir=\$(mktemp -d)" 0 "Creating tmp directory" rlRun "pushd $TmpDir" rlPhaseEnd